> ## Documentation Index
> Fetch the complete documentation index at: https://docs.browserbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Web Bot Auth

> Give your browser traffic a verifiable identity with Web Bot Auth. Learn how request signing works and request beta access.

Web Bot Auth helps your browser agent identify itself to websites. Paired with [Verified](/platform/identity/verified-customization), it helps your agent access protected sites while website owners stay in control of access.

<Card title="Request beta access" icon="rocket" href="https://www.browserbase.com/contact-web-bot-auth">
  Contact Browserbase to enable Web Bot Auth for your account.
</Card>

## Why Web Bot Auth?

Websites need a reliable way to recognize your browser agent. Anyone can copy a User-Agent header, and shared IP addresses can make unrelated traffic look alike. Web Bot Auth adds a cryptographic identity that participating sites can verify, giving them a stronger basis for deciding which traffic to allow.

## How it works

Web Bot Auth builds on [HTTP Message Signatures (RFC 9421)](https://www.rfc-editor.org/rfc/rfc9421.html). Its [IETF protocol specification](https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/) remains a work in progress.

1. **Publish a public key.** The signer keeps a private key and publishes the matching public key in a directory, such as `/.well-known/http-message-signatures-directory`.
2. **Sign outgoing traffic.** The signer uses the private key to sign selected HTTP components and attaches signature headers to the request.
3. **Verify the signature.** The website or its bot-protection provider retrieves the public key and checks the signature and its validity period.
4. **Apply access policy.** The website decides whether to allow, challenge, rate-limit, or block the traffic.

### Signature headers

| Header | Purpose |
| - | - |
| `Signature-Agent` | Points the verifier to the signer's public keys. |
| `Signature-Input` | Identifies the signed components, key, and signature parameters. |
| `Signature` | Carries the cryptographic signature. |

Signing `@authority` binds a signature to the destination host. The `created` and `expires` parameters bound its lifetime. These checks limit where and when a signature works; they don't prevent all replay within that scope.

## Identity and access

A valid signature proves that a holder of the corresponding private key signed the covered components. The website still decides whether to trust that identity and what it can do.

Web Bot Auth doesn't establish a human user's identity, grant permission to act on their behalf, or replace a website's login flow. Use [authentication management](/platform/identity/authentication) for sign-in and account access.

Support depends on the destination website and its bot-protection provider. Even when a site recognizes signed traffic, its access rules still apply.

## How to use Web Bot Auth with Browserbase

[Request beta access](https://www.browserbase.com/contact-web-bot-auth) to discuss enablement for your account and the websites your browser agents need to access.

If a site still blocks your session, contact [Browserbase support](mailto:support@browserbase.com) with the destination URL and session ID.

If you operate the destination website, check whether your bot-protection provider supports Web Bot Auth verification. Configure access rules for the identities you trust, and retain the rate limits and account permissions your application requires.

## Next steps

<CardGroup cols={2}>
  <Card title="Verified" icon="shield-check" href="/platform/identity/verified-customization">
    Configure Verified browser sessions for protected websites.
  </Card>

  <Card title="Authentication management" icon="lock" href="/platform/identity/authentication">
    Handle sign-in, 2FA, and OAuth flows in your browser sessions.
  </Card>
</CardGroup>
