Free tool
Web Bot Auth signature checker
For site owners: check whether a request from an AI agent carries a valid Web Bot Auth signature (RFC 9421 HTTP Message Signatures, draft-ietf-webbotauth-httpsig-protocol). The check runs in your browser; what you paste is never sent anywhere.
The request
What is checked
tag="web-bot-auth",createdandexpires(a window of 1 hour or less, not expired, not from the future), andkeyid, the RFC 7638 thumbprint of a key in the directory.- The covered components include
@authority(or@target-uri) and the request's ownSignature-Agentmember; members with an unsupported type or a path are ignored. - The RFC 9421 signature base is rebuilt from the exact
Signature-Inputtext and verified with Ed25519. - Not checked: replay. This tool keeps no record of requests, so it cannot tell one it has seen before. Your server must keep nonces.
Fetching the directory
Your browser cannot read another site's directory, so the button asks our server to fetch it: https://<agent origin>/.well-known/http-message-signatures-directory, https on port 443 only, public host names only (no IP addresses, localhost or internal names), no redirects, 5 seconds, 64 KB at most, cached for 10 minutes, 10 lookups a minute per network. Only the agent's origin is sent to us, and nothing is stored.
On your own server
The same verification code is in the repository as a zero-dependency SDK: sdk/websig.mjs to sign and verify, and sdk/verifier.mjs with a drop-in wrapper for Fetch handlers and Express, SSRF-safe directory fetching (on Node the connection goes only to the address it checked) and nonce stores for D1, KV or memory. It verifies locally; it never calls us.