Managed rule groups

Every published managed rule group, its rules and default actions, and how to reference, pin and override them.

A managed rule group is a named, versioned list of rules. Reference it in a rule set instead of copying its rules:

JSON
{"group": "agentgate-core", "version": 1, "overrides": {"agent_class": "count"}}
  • The version is required. Unknown groups, versions and override targets are rejected.
  • Published versions never change (a digest test pins them), so moving to a new version is an explicit edit.
  • overrides changes single rules' actions, for example to count while you evaluate them. scope_down on the reference is ANDed into every rule of the group.
  • Rule names, and so the agentgate:rule:<name> labels, are the same as when the rules are written out.
  • GET /v1/console/managed-groups (operators: /v1/admin/managed-groups) lists every group with its expanded rules. GET …/rules returns the references as written.

The built-in default rule set is agentgate-core@1, agentgate-agents@1 and agentgate-gateway@1, in that order. agentgate-bot-control@1 and agentgate-anonymity@1 are opt-in.

agentgate-core@1

The browser-check rules, evaluated on /submit (the form and every SDK verification), plus the per-agent policy rules, which apply on every route and stay dormant until a site configures an agent policy.

RuleActionMatches
honeypotdropa hidden honeypot field was filled
missing_proofblock 403no proof of work
invalid_proofblock 403a proof that does not verify
agent_policy_unverified_blockblock 403unverified AI claim, policy block
agent_policy_unverified_chargeblock 402unverified AI claim, policy charge
agent_policy_unverified_challengechallengeunverified AI claim, policy challenge
agent_policy_deniedblock 403verified agent not permitted this action
agent_policy_quotablock 429over the agent's per-site quota
agent_policy_payment_invalidblock 400malformed, conflicting or unsigned price offer
agent_policy_payment_requiredblock 402priced action without an acceptable offer
agent_policy_allowedallowverified agent permitted this action
instrument_invalidblock 403a wrong instrumentation answer
instrument_missingchallengeno instrumentation answer
instrument_slowchallengethe instrumentation answer took too long
known_patternblockthe content matches a known spam pattern
ip_soft_limitchallengethe address is over its soft rate budget
model_thresholdblockthe content model score is high
sdk_late_initchallengeexecute() ran without init()
agent_classchallengethe behaviour model classifies the visit as an agent or a bot
env_watchcountany browser environment finding (for the audit)
env_automationchallengedefinitive automation markers, such as navigator.webdriver or headless
env_cdp_low_pointerchallengea DevTools-protocol client and almost no pointer movement
env_cdp_stealthchallengea DevTools-protocol client with patched browser functions
env_agent_domchallengeDOM markers left by known browser agents
pat_attested_skip_checkcounta Private Access Token attested the device
tls_non_browserchallengea browser User-Agent over a non-browser TLS fingerprint
challenge_requiredchallengethe bot-risk score is high
rate_limitedblock 429session or global rate budget exceeded

Challenges in this group are skipped for a session that has passed the visible check (label agentgate:session:passed).

agentgate-agents@1

Web Bot Auth policy for the agent API, /agent/submit.

RuleActionMatches
agent_signature_invalidblock 401a bad, expired or replayed signature
agent_authenticatedallowa verified agent (agentgate:agent:verified:*) or a valid shared key
agent_unknown_keyblock 401the key is not known for its origin
agent_unauthenticatedblock 401no signature, or a wrong shared key

agentgate-gateway@1

Authorization at /v1/gateway/check.

RuleActionGateway reason
gateway_agent_signature_invalidblockagent_signature_invalid (includes a body digest mismatch)
gateway_rate_limitedblockrate_limited
gateway_receipt_rejectedchallengethe token's code: invalid_token, expired_token, token_used, action_mismatch, origin_mismatch
gateway_browser_evidence_requiredchallengereceipt_required (or the clearance's code) on a browser route with neither a valid token nor clearance

agentgate-bot-control@1

User-Agent and crawler identity checks, from the bot catalogue and threat intelligence.

RuleActionMatches
bot_ua_mismatchblock 403the User-Agent claims one catalogued bot while a signature proves another
bot_ip_mismatchblock 403a crawler User-Agent from outside its operator's published ranges
bot_http_libraryblock (/submit)an HTTP library User-Agent (curl, python-requests, …)
bot_headless_browserchallenge (/submit)a headless browser User-Agent, unless verified
bot_automation_flagchallenge (/submit)the automation flag signal
bot_unverified_aichallenge (/submit)an AI assistant or crawler User-Agent that nothing verifies

agentgate-anonymity@1

RuleActionMatches
anonymity_torchallenge (/submit)a current Tor exit
anonymity_datacentercount (/submit)an address in a cloud provider's ranges, unless a verified bot
ip_reputation_highchallenge (/submit)a high IP reputation score from recent decisions

Datacenter addresses are normal for agents and crawlers, so anonymity_datacenter counts rather than blocks; override its action if your site should treat them differently.

View as Markdown