# Signed agents

> Why AgentGate gives AI agents that sign their requests a lane of their own, and how that lane is governed.

A growing share of traffic is AI agents: crawlers, assistants fetching a
page for a person, and browser agents acting in someone's Chrome. Treating
all of them as bots to be blocked stops the useful ones; treating all of
them as people lets anyone in. AgentGate separates them by **identity**.

## Declared, verified, unverified

| Kind | How AgentGate sees it | Default handling |
| --- | --- | --- |
| **Verified agent** | A valid [Web Bot Auth](/docs/web-bot-auth) signature from a known key or an allow-listed key directory | Admitted per the site's [agent policy](/docs/agent-policy); never shown a human check; rate-limited per identity |
| **Verified crawler by IP** | A User-Agent naming a catalogued crawler, from that operator's published IP ranges (or, for Googlebot, Bingbot and Applebot, forward-confirmed reverse DNS) | Labelled `agentgate:bot:verified:ip`; rules decide |
| **Unverified claim** | A User-Agent that names an AI agent or crawler (`GPTBot`, `ChatGPT-User`, `PerplexityBot`, …) with no proof | Challenged by default; a site can block, charge or count instead |
| **Undeclared automation** | Headless browsers, HTTP libraries, CDP-driven or stealth browsers, LLM agents in a person's browser | Scored by the browser check and rules; challenged or blocked |

## Web Bot Auth in one paragraph

Web Bot Auth is an IETF draft built on HTTP Message Signatures (RFC 9421):
the agent signs each request with an Ed25519 key, names its key directory
in `Signature-Agent`, and tags the signature `web-bot-auth`. AgentGate
fetches allow-listed directories (or uses keys the operator registered),
checks the signature covers the right parts of the request, and rejects
expired signatures and reused nonces. A verified request carries the label
`agentgate:agent:verified:<name>`.

## What a site can do with identity

- **Allow or deny per action.** ChatGPT may call `agent_submit`, an unknown
  crawler may read nothing ([agent policy](/docs/agent-policy)).
- **Quota per agent.** Each agent gets its own per-minute budget and replay
  namespace.
- **Price access.** Answer `402 Payment Required` with pay-per-crawl
  headers; AgentGate signals the price, it does not process payment
  ([pay per crawl](/docs/pay-per-crawl)).
- **Publish tools.** A manifest at `/.well-known/agentgate-tools.json`
  tells agents which endpoints they may call and how to sign
  ([declared tools](/docs/agent-tools)).
- **Hand off to a person.** When a check is needed, the agent gets a link
  or QR code for its person to complete on their own device
  ([human handoff](/docs/human-handoff)).
- **Prove what happened.** Responses to authenticated agents carry a signed
  receipt of the decision ([signed receipts](/docs/agent-receipts)).

## Limits

- No third-party agent has yet sent a real signed request to an AgentGate
  gateway; interoperability is tested against published test vectors and
  captured key directories.
- RSA-PSS signatures and some `Signature-Agent` forms are not supported
  (they are ignored, not accepted).
- A stolen agent private key is valid until the agent's directory rotates it.
