Skip to content

Good Bots, Bad Bots and AI Agents: How to Verify Agent Traffic Without Blocking Customers

How signed agent requests, Web Bot Auth and Visa's Trusted Agent Protocol let you allow trusted AI shopping agents and still stop malicious bots.

01

Quick answer

Treat AI agents as a third category alongside humans and bad bots. Signed requests make that practical: ChatGPT agent and other operators sign their HTTP requests (RFC 9421 HTTP Message Signatures) and publish keys, the IETF's Web Bot Auth working group is standardizing the approach, and Visa's Trusted Agent Protocol uses it for agent checkout. Verify signatures at your CDN or edge, allow verified agents on browsing and cart paths, keep payment and account changes behind customer confirmation and normal fraud checks, and rate-limit or challenge unsigned automation. Do not rely on user agent strings, and do not block all automation by default.

02

Why blanket bot blocking is becoming expensive

For years the safe default was simple: anything that is not a browser operated by a person is suspicious. Credential stuffing, scalping, scraping and card testing made that a reasonable rule, and bot-protection products are good at enforcing it.

Agentic commerce breaks the rule. When a shopper asks an assistant to find a product, compare options and put it in a cart, the request reaching your store comes from automation acting with permission. If your defences treat it like a scraper, you lose the sale and never see it in analytics. The same applies to travel bookings, restaurant reservations, appointment scheduling and B2B reordering. Our agentic commerce guide covers how these purchases work end to end.

TrafficIntentDesired treatment
Customer in a browserBuy, book, enquireAllow; normal fraud checks
Search and AI search crawlersIndex contentAllow on public pages; verify by IP or signature
Verified AI agent acting for a userBrowse, compare, add to cart, check out with confirmationAllow on defined paths; confirm sensitive steps
Unverified automationUnknownRate-limit, challenge, monitor
Malicious botsScrape, stuff credentials, test cards, hoard stockBlock
03

Why user agents and IP lists are not enough

A user agent string is self-declared; any script can claim to be ChatGPT. IP allowlists are better for crawlers (OpenAI, Google and others publish their crawler ranges), but they are brittle for agents that run on shared cloud infrastructure, and they say nothing about which operator or product sent a specific request. Verifying claimed crawlers by IP or reverse DNS remains good practice, but for agents acting on behalf of people you need something stronger.

04

How signed agent requests work

HTTP Message Signatures (RFC 9421) let a client sign selected parts of an HTTP request with a private key. The server verifies the signature with the matching public key. For bots and agents, the operator publishes its public keys in a directory at a well-known URL and adds headers that tell the server where to find them.

OpenAI documents this for ChatGPT agent: each request carries `Signature` and `Signature-Input` headers plus a `Signature-Agent` header set to `"https://chatgpt.com"`, and the keys are published at a well-known HTTP message signatures directory on chatgpt.com. A server verifies that the Signature-Agent value matches, fetches the key, and checks the signature as defined in RFC 9421.

The IETF chartered the Web Bot Auth (webbotauth) working group to standardize these methods for crawlers, archivers and AI agents, with milestones through 2026 for authentication techniques, conveying bot information and operational best practice. Several CDN and bot-management providers already verify signed agents for their customers, which means many merchants can enable verification as a setting rather than writing code.

Simplified headers on a signed agent request
GET /products/trail-shoe-42 HTTP/1.1
Host: shop.example.com
Signature-Agent: "https://chatgpt.com"
Signature-Input: sig1=("@authority" "@method" "@path" "signature-agent");created=1791400000;expires=1791400300;keyid="…";tag="web-bot-auth"
Signature: sig1=:BASE64SIGNATURE…:

Worth noting

The header example is illustrative and shortened. Use your CDN's built-in verification or a maintained library rather than writing signature verification from scratch.

05

Payments: Visa's Trusted Agent Protocol and similar efforts

Card networks have the same problem at checkout: was this purchase made by a legitimate agent acting for a real cardholder? Visa announced its Trusted Agent Protocol in October 2025, developed with Cloudflare and with feedback from payment providers and platforms including Adyen, Checkout.com, Stripe, Shopify, Worldpay and Microsoft. It lets approved agents pass signed information to merchants so they can tell legitimate agents from malicious bots, for both guest and logged-in checkout. Visa describes it as built on HTTP Message Signatures and aligned with Web Bot Auth.

Mastercard has a parallel programme (Agent Pay), and Google's Agent Payments Protocol (AP2) focuses on proving the user authorized a purchase. For merchants, the practical message is the same: these schemes are arriving through payment providers and CDNs, so ask yours what they support rather than building to a protocol directly.

06

A policy that allows agents and stops abuse

Write the policy by path and action, not by bot name.

Path or actionVerified agentUnverified automation
Public pages, product and category pagesAllowAllow with rate limits
Search and filtersAllow with rate limitsRate-limit tightly or challenge
Add to cartAllowChallenge on unusual patterns (stock hoarding)
Login and account creationAllow via user's own credentials or OAuth; monitorChallenge; protect against credential stuffing
Checkout and paymentAllow with customer confirmation and normal fraud screeningChallenge or block
Account changes, refunds, addressesRequire step-up confirmation by the customerBlock

Key takeaway

A valid signature tells you who operates the agent, not whether this particular request is legitimate. Keep authentication, fraud screening and confirmation steps in place for consequential actions.

07

Implementation steps

  • Measure first: identify automated traffic by user agent, signature headers and behaviour in your CDN and server logs
  • Ask your CDN or bot vendor whether it verifies signed agents (Web Bot Auth, ChatGPT agent) and how to configure policies
  • Ask your payment provider about agent checkout support (Visa TAP, Mastercard Agent Pay, AP2) and fraud rules for agent-initiated orders
  • Define the path policy above and apply it at the edge
  • Label agent sessions in analytics so you can see agent-assisted orders and conversion
  • Make confirmation steps explicit so agents can surface them to users (see how AI agents use websites)
  • Review monthly: new operators, false positives, abuse patterns

Running a store that needs to welcome AI shoppers?

ZSpace Labs configures bot policies, agent-ready checkout flows and analytics for Shopify and custom stores. See Shopify development services.

Start a Project
08

Limitations and open questions

Signed agents are new. Not every operator signs requests yet, standards are still being finalized, and the long tail of smaller agents will take time to adopt them. Signatures also do not answer every question: an agent might be operated by a reputable company and still be misused by its user. Expect to run signature verification alongside behavioural bot detection for some time, and to adjust the policy as payment networks and platforms settle on their schemes.

For crawler-specific controls, see AI crawlers and robots.txt. For general store protection, see ecommerce security and ecommerce fraud detection.

09

Conclusion

The old rule (humans good, automation bad) no longer fits a world where customers delegate shopping and booking to assistants. Verify agents cryptographically where operators support it, allow them on low-risk paths, keep customers in control of payment and account changes, and keep blocking the abuse you were blocking before. That keeps the door open for AI-assisted customers without opening it to everyone.

FAQ

Common questions.

User agent strings are easy to fake. Reputable agent operators increasingly sign their requests with HTTP Message Signatures (RFC 9421) and publish their public keys, so your server or CDN can verify cryptographically which operator sent a request. Combine that with behaviour-based bot detection for everything unsigned.

Get in touch

Have a project in mind?

Whether you're building a new digital product, improving an existing website, or looking to automate part of your business — let's talk.