What is AgentGate?

Bot and agent protection for forms and APIs: an invisible browser check, a policy gateway, and a lane for AI agents that sign their requests.

AgentGate tells people, declared AI agents and undeclared automation apart, and lets each through the right door. It is a hosted service: you add your site in the console and AgentGate runs the checks for you (request access).

It protects your site in three ways. They share one site configuration, one rule engine and one dashboard, so you can start with one and add the others.

IntegrationUse it forWhat you add
Browser widget + siteverifyForms and API calls made from your own pagesA script tag and one element on the page; one call to POST /v1/siteverify on your server
GatewayAny HTTP app, including routes browsers never callnginx auth_request (or Go / Node middleware) that asks GET /v1/gateway/check before forwarding
Signed agentsAI agents and crawlers you want to admit on your termsA per-site agent policy; agents sign requests with Web Bot Auth

What visitors see

Most people see nothing. The widget runs a small proof of work and collects interaction timings (never what is typed) while the page is open. When the evidence looks unusual, AgentGate asks for a short press-and-hold check, with a keyboard option and a "Verify another way" alternative that needs no pointer at all. See How the check works.

What your server sees

The widget hands your form a single-use token. Your server sends it to POST /v1/siteverify with the site's backend secret and acts only when the answer is "success": true. The widget alone enforces nothing.

Important

Server-side validation is mandatory. A form that accepts a request without calling /v1/siteverify is not protected, whatever the page shows.

What agents get

Agents that sign their requests with Web Bot Auth are verified by key, rate-limited per identity and never shown a human check. A site can allow or deny each agent per action, put a price on actions (402 Payment Required, pay-per-crawl headers), publish the tools an agent may call, and hand a challenge to the agent's person on their phone.

Every decision is explained

Each request gets labels (for example agentgate:proof:missing or agentgate:agent:verified:chatgpt) and an ordered, WAF-style rule set turns labels into allow, challenge, block, drop or count. The dashboard shows the labels, the rule that decided, the scores and the model version for every decision.

Start safely

Every new site starts in monitor mode: every verification passes and AgentGate records what it would have done. Switch to enforce once the would-have decisions look right.

Honest limits

  • The browser check raises the cost of automation. It is not proof that a person is present: signals are collected in the browser and a determined attacker can forge them.
  • The hosted service runs in one region today; multi-region hosting is on the roadmap.
  • Models are trained on synthetic data; unmeasured detectors ship in count mode. See the threat model.

View as Markdown