Free tool

Web Bot Auth signature checker

For site owners: check whether a request from an AI agent carries a valid Web Bot Auth signature (RFC 9421 HTTP Message Signatures, draft-ietf-webbotauth-httpsig-protocol). The check runs in your browser; what you paste is never sent anywhere.

The request

Fetch it from the agent's origin, or paste it.

What is checked

Fetching the directory

Your browser cannot read another site's directory, so the button asks our server to fetch it: https://<agent origin>/.well-known/http-message-signatures-directory, https on port 443 only, public host names only (no IP addresses, localhost or internal names), no redirects, 5 seconds, 64 KB at most, cached for 10 minutes, 10 lookups a minute per network. Only the agent's origin is sent to us, and nothing is stored.

On your own server

The same verification code is in the repository as a zero-dependency SDK: sdk/websig.mjs to sign and verify, and sdk/verifier.mjs with a drop-in wrapper for Fetch handlers and Express, SSRF-safe directory fetching (on Node the connection goes only to the address it checked) and nonce stores for D1, KV or memory. It verifies locally; it never calls us.