Standards & ProtocolsCrawlers & Content ControlsAgentic Web IETF Web Bot Auth Working Group ·

IETF Web Bot Auth WG Officially Adopts HTTP Message Signatures Protocol Draft

Open source ↗

Development

The IETF Web Bot Auth Working Group has formally adopted the core specification for cryptographically signing automated web requests. The individual submission was re-indexed as the working group document draft-ietf-webbotauth-httpsig-protocol-00 (‘HTTP Message Signatures for automated traffic’) on September 1, 2026. This marks the transition of the protocol from an individual draft into the working group’s official standards track.

Why it matters

As web publishers struggle with scraping volume and bot spoofing, a standardized cryptographic authentication protocol under active IETF development provides a path toward verifiable, accountable crawler identification at scale.

Trend impact

  • cryptographic-bot-verification
  • ietf-standardization
  • agent-authentication

Evidence

View raw diff
--- prev
+++ curr
@@ -12,7 +12,15 @@
 Status
 IPR
 AD/Shepherd
-Related Internet-Drafts and RFCs (11 hits)
+Active Internet-Draft (1 hit)
+44 pages
+draft-ietf-webbotauth-httpsig-protocol-00
+HTTP Message Signatures for automated traffic
+2026-09-01
+New
+I-D Exists
+WG Document
+Related Internet-Drafts and RFCs (10 hits)
 6 pages
 draft-farzdusa-webbot-datacollection-00
 Best Practices for Responsible Web Data Collection
@@ -27,12 +35,6 @@
 draft-illyes-webbotauth-jafar-00
 A JSON-Based Format for Publishing IP Ranges of Automated HTTP Clients
 2026-04-21
-I-D Exists
-44 pages
-draft-meunier-webbotauth-httpsig-protocol-02
-HTTP Message Signatures for automated traffic
-2026-08-18
-New
 I-D Exists
 26 pages
 draft-meunier-webbotauth-registry-03