← Back to Blog

Announcements

Web Bot Auth: How hCaptcha Supports it

A signed agent request passes through signature verification and a separate customer policy decision.

hCaptcha Enterprise now supports Web Bot Auth (WBA), giving partner agent platforms a cryptographic way to identify their traffic. A verified signature confirms request provenance. Your policies still determine whether the request can proceed.

A single agent platform can serve both shoppers and attackers. hCaptcha combines signed provenance with user-level risk signals so sites can assess individual requests without having to accept or reject every user of an agent.

What a signature tells you

Web Bot Auth is an IETF draft built on HTTP Message Signatures. An agent platform signs selected parts of an outbound request with its private key. The verifier checks that signature against the corresponding public key.

A User-Agent string can be copied. A valid signature proves possession of a signing key and protects the covered request components against modification. It does not prove good intent, user consent, or permission to perform an action.

Agent provenance and user risk signals feed hCaptcha's risk assessment and the customer's policy decision.
A signed request still needs a risk assessment and an access decision.

How hCaptcha uses WBA

hCaptcha detects agents through its own analysis. WBA adds a provenance signal for agent services that partner with us to authenticate their traffic. Detection does not depend on an agent volunteering its identity.

hCaptcha customers control which agents may access specific flows and can block unsigned agent requests entirely. A signature can increase confidence in attribution while the request remains subject to hCaptcha's risk assessment and the customer's policy.

For example, a merchant could permit a signed shopping agent to browse products while restricting automated inventory reservations.

Limitations of Web Bot Auth

Web Bot Auth was narrowly designed for a specific problem: authenticating single operators of bots. For example, the Google crawler is run by one entity. This is almost useless when it comes to agent platforms, where millions of people may be taking actions.

hCaptcha has designed privacy-preserving risk signal extensions for this reason, and is working with all major agent platforms to implement them in advance of future IETF standardization.

Assess the user behind the agent

Our partner integration adds an encrypted header containing a temporary, time-variant, opaque user identifier and coarse, non-identifying risk signals supplied by the agent platform.

This lets hCaptcha provably distinguish users of the same platform, so one user's abuse need not force a blanket decision against everyone using that agent. Platforms retain the mapping to their own users. They do not send raw account IDs, email addresses, phone numbers, or unkeyed hashes of them; the identifier is both temporary and completely non-reversible.

Platforms generate the header in trusted outbound infrastructure and cover it with their WBA signature. hCaptcha's integration binds the signals to the request and performs checks like signature validity, freshness, and replay protection before using them. The supplied signals inform risk assessment, but do not replace it; even a platform's highest trust category cannot override customer policy or contradictory hCaptcha evidence.

Enrolling with hCaptcha

Agent platforms can contact hCaptcha support to discuss partner integration.

Enabling WebMCP verification tools in your hCaptcha Enterprise account

For hCaptcha Enterprise customers who wish to control tools exposed in the browser, see hCaptcha's WebMCP support.