Skip to main content
Web Bot Auth helps your browser agent identify itself to websites. Paired with Verified, it helps your agent access protected sites while website owners stay in control of access.

Request beta access

Contact Browserbase to enable Web Bot Auth for your account.

Why Web Bot Auth?

Websites need a reliable way to recognize your browser agent. Anyone can copy a User-Agent header, and shared IP addresses can make unrelated traffic look alike. Web Bot Auth adds a cryptographic identity that participating sites can verify, giving them a stronger basis for deciding which traffic to allow.

How it works

Web Bot Auth builds on HTTP Message Signatures (RFC 9421). Its IETF protocol specification remains a work in progress.
  1. Publish a public key. The signer keeps a private key and publishes the matching public key in a directory, such as /.well-known/http-message-signatures-directory.
  2. Sign outgoing traffic. The signer uses the private key to sign selected HTTP components and attaches signature headers to the request.
  3. Verify the signature. The website or its bot-protection provider retrieves the public key and checks the signature and its validity period.
  4. Apply access policy. The website decides whether to allow, challenge, rate-limit, or block the traffic.

Signature headers

Signing @authority binds a signature to the destination host. The created and expires parameters bound its lifetime. These checks limit where and when a signature works; they don’t prevent all replay within that scope.

Identity and access

A valid signature proves that a holder of the corresponding private key signed the covered components. The website still decides whether to trust that identity and what it can do. Web Bot Auth doesn’t establish a human user’s identity, grant permission to act on their behalf, or replace a website’s login flow. Use authentication management for sign-in and account access. Support depends on the destination website and its bot-protection provider. Even when a site recognizes signed traffic, its access rules still apply.

How to use Web Bot Auth with Browserbase

Request beta access to discuss enablement for your account and the websites your browser agents need to access. If a site still blocks your session, contact Browserbase support with the destination URL and session ID. If you operate the destination website, check whether your bot-protection provider supports Web Bot Auth verification. Configure access rules for the identities you trust, and retain the rate limits and account permissions your application requires.

Next steps

Verified

Configure Verified browser sessions for protected websites.

Authentication management

Handle sign-in, 2FA, and OAuth flows in your browser sessions.