The web is filling with automation that identifies itself. Instead of pretending to be a browser, a well-behaved agent can sign its requests and publish the key that verifies them. That changes what "bot detection" can mean.
What Web Bot Auth is
Web Bot Auth applies HTTP Message Signatures to automated requests. An agent signs parts of its request with a private key and publishes the matching public key in a directory — the .well-known JWKS document for that agent. A verifier fetches the directory, checks the signature, and learns something a user-agent string can never tell it: this request really came from the party it claims.
Volance verifies these signatures and also publishes its own key material at a well-known directory, so other parties can identify Volance's traffic in turn.
Three outcomes, three responses
Signature verification is deliberately not binary:
- Verifies. The signature matches a published or registered key. The request is treated as authorized_agent — automation allowed through by policy, without ever being called human.
- Known key, bad signature. The key is known but the signature fails. That is spoofed disclosure, and it is capped hard. Claiming an identity you cannot back up is worse than staying anonymous.
- Unresolvable signer. We cannot find a key for the signer. We ignore it rather than penalise it, so an agent that has not published keys yet is not punished for trying.
That third case is the one people get wrong. Penalising every unverifiable signature turns a new standard into a trap for early adopters. Ignoring an unresolvable signer keeps the door open while still catching outright spoofing.
Why this matters for policy
Once agents can prove who they are, your policy can stop treating all automation as a threat. You can write rules like: admit verified agents, flag unknown automation, block spoofed disclosure. The distinction between agent and bot becomes something you can act on rather than a nuance you average away.
It also shrinks the false-positive surface. A legitimate partner's agent no longer looks identical to a scraper, because one of them is willing to sign and the other is not.
An evolving standard
Web Bot Auth is still developing, and not every agent publishes keys yet. Treat signature verification as one high-quality signal among many rather than the whole decision — and keep the policy on your server, where you can adjust it as the ecosystem matures.
Signed automation is not a threat to sort out later. It is the clearest example of why "human or bot" was never the whole picture, and why separating agents from bots makes a detection system more useful, not less.
Frequently asked
What happens if an agent has not published keys yet?
Volance ignores an unresolvable signer rather than penalising it. The agent is treated as unknown automation, not as spoofed.
Does a verified agent count as human?
No. It returns authorized_agent: automation that checked out, which your policy can allow. It is never labelled human.