§56 · Lane 8 — Agent Infrastructure Standards & Toolchain
IETF Internet-Draft — Web Bot Auth Architecture verifiable agent identity for metered and gated access
Meunier et al. (2026) · draft-ietf-webbotauth-httpsig-protocol-00
Bibliographic data
- Title
- Web Bot Auth — HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol-00, 1 September 2026)
- Authors / Issuing body
- Thibault Meunier (Cloudflare) and contributors; co-authored with Google
- Venue / Publisher
- Internet Engineering Task Force (IETF) — Web Bot Auth (webbotauth) Working Group document
- Year
- 2026
- Designation
- Internet-Draft
- Licence
- IETF Trust Legal Provisions (BCP 78)
How to cite
Meunier et al. (2026). Web Bot Auth — HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol-00, 1 September 2026). Internet Engineering Task Force (IETF) — Web Bot Auth (webbotauth) Working Group document. https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/.
An IETF Internet-Draft specifying how an automated agent cryptographically signs its outbound requests using Ed25519 over RFC 9421 HTTP Message Signatures, so a verifying origin or fronting edge can confirm the agent's identity. Adopted by the IETF Web Bot Auth (webbotauth) Working Group on 1 September 2026 as draft-ietf-webbotauth-httpsig-protocol-00, superseding the individual drafts that preceded it. It is a working-group document on the standards track — not yet a published standard.
Why it matters for NETEVO
Verifiable agent identity is the prerequisite for every priced or gated access decision: an edge cannot charge, tier or admit an agent it cannot identify. This draft is the request-signing scheme that the largest edge operators already treat as their strongest verification tier — a signed request is admitted to the verified tier, while an unsigned one falls to a heuristic, spoofable tier.
The identity layer matured materially in September 2026. The work was adopted by the IETF Web Bot Auth Working Group on 1 September 2026 and is now a working-group document on the standards track, where previously it was an individual submission with no formal standing. That is a genuine change in the substrate: verified agent identity is now being progressed through the IETF process rather than merely proposed to it.
The qualifications that remain are the ones that matter for planning. Working-group adoption is not publication: the document is an Internet-Draft, it binds nobody, and there is no RFC. The verified-agent registry is still not cross-vendor, and the scheme signs the operator rather than the end user. Any architecture that meters or gates agent access should treat verified identity as a maturing dependency rather than a settled one — further along than it was, but not finished.
The same identity primitive underpins both metered content access and agent-mediated transactions, which is why it bridges the agent-infrastructure and content-economy material.
Where NETEVO applies this
- AI Traffic Monetisation Whitepaper — load-bearing — verifiable agent identity is the prerequisite for the verified-versus-unverified pricing tier
- Agent-Ready Lending Whitepaper — supporting — the shared agent-identity rail beneath agent-mediated credit
Who acts on this
Reading this usually means something has forced the question — a listing, an audit finding, a procurement questionnaire, a regulator's letter. The role pages below set out what NETEVO does about it, including where we would tell you not to engage.