§56 · Lane 8 — Agent Infrastructure Standards & Toolchain

IETF Internet-Draft — Web Bot Auth Architecture verifiable agent identity for metered and gated access

Meunier et al. (2026) · draft-ietf-webbotauth-httpsig-protocol-00

Internet-Draft Tier 1 Lane 8 IETF Trust LP
Read on publisher · IETF Trust LP

Bibliographic data

Title
Web Bot Auth — HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol-00, 1 September 2026)
Authors / Issuing body
Thibault Meunier (Cloudflare) and contributors; co-authored with Google
Venue / Publisher
Internet Engineering Task Force (IETF) — Web Bot Auth (webbotauth) Working Group document
Year
2026
Designation
Internet-Draft
Licence
IETF Trust Legal Provisions (BCP 78)

How to cite

Meunier et al. (2026). Web Bot Auth — HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol-00, 1 September 2026). Internet Engineering Task Force (IETF) — Web Bot Auth (webbotauth) Working Group document. https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/.

An IETF Internet-Draft specifying how an automated agent cryptographically signs its outbound requests using Ed25519 over RFC 9421 HTTP Message Signatures, so a verifying origin or fronting edge can confirm the agent's identity. Adopted by the IETF Web Bot Auth (webbotauth) Working Group on 1 September 2026 as draft-ietf-webbotauth-httpsig-protocol-00, superseding the individual drafts that preceded it. It is a working-group document on the standards track — not yet a published standard.

Why it matters for NETEVO

Verifiable agent identity is the prerequisite for every priced or gated access decision: an edge cannot charge, tier or admit an agent it cannot identify. This draft is the request-signing scheme that the largest edge operators already treat as their strongest verification tier — a signed request is admitted to the verified tier, while an unsigned one falls to a heuristic, spoofable tier.

The identity layer matured materially in September 2026. The work was adopted by the IETF Web Bot Auth Working Group on 1 September 2026 and is now a working-group document on the standards track, where previously it was an individual submission with no formal standing. That is a genuine change in the substrate: verified agent identity is now being progressed through the IETF process rather than merely proposed to it.

The qualifications that remain are the ones that matter for planning. Working-group adoption is not publication: the document is an Internet-Draft, it binds nobody, and there is no RFC. The verified-agent registry is still not cross-vendor, and the scheme signs the operator rather than the end user. Any architecture that meters or gates agent access should treat verified identity as a maturing dependency rather than a settled one — further along than it was, but not finished.

The same identity primitive underpins both metered content access and agent-mediated transactions, which is why it bridges the agent-infrastructure and content-economy material.

Where NETEVO applies this

Who acts on this

Reading this usually means something has forced the question — a listing, an audit finding, a procurement questionnaire, a regulator's letter. The role pages below set out what NETEVO does about it, including where we would tell you not to engage.