Detection

AI agent detection that lets verified agents in and keeps impostors out

AI agent detection identifies software that browses and acts for a person, such as ChatGPT's cloud browser or an agentic browser, and checks whether it is who it claims to be. Verified agents prove identity with cryptographic signatures or their operator's published IP ranges. Kavra separates verified agents from unverified claims and impostors, and you choose allow, check or block.

POST /checkoutAllowed

Verified OpenAI agent, signed

  • Valid Web Bot Auth signature
  • IP in operator's published range
  • Acting in a known customer session
Risk12
Your actionAllow per agent policy
Who it hits
E-commerce, travel, SaaS, marketplaces, publishers
What is at stake
Agent-driven sales on one side, abuse on the other
Agents seen
Hosted agents, agentic browsers, open-source frameworks
Where to decide
Per project, per agent, per endpoint

What is an AI agent on your website?

An AI agent is software that uses a language model to carry out a task on the web for a person: search for a product, compare prices, fill a form, book a table or complete a checkout. Unlike a crawler that reads pages to build an index, an agent acts. It clicks, types, logs in and sometimes pays.

Agents reach your site in three main ways. Hosted agents, such as the cloud browser in OpenAI's ChatGPT or Google's Gemini agent, run a browser in the operator's cloud. Agentic browsers, such as Perplexity Comet, run on the user's own computer, inside a real browser, next to the user's own tabs. Open-source frameworks in the style of browser-use let anyone wire a model to an automated browser and point it at any site, for any purpose.

Verified, unverified and impostor agents

The name an agent gives is a claim, not proof. Sort agent traffic by what it can prove.

TypeWhat you seeWhat it meansSensible default
Verified agentA declared agent with a valid cryptographic signature, or an IP inside the operator's published rangesThe operator stands behind the requestAllow, with limits you set
Declared but unverifiedSays it is an agent, but offers no signature and comes from outside known rangesCould be honest but unsigned, or a copy of the nameCheck: rate-limit or challenge
ImpostorClaims a known agent or crawler name, but the signature fails or the IP belongs to someone elseSomeone is borrowing a trusted nameBlock
Undeclared automationLooks like a person in a normal browser, but behaves like softwareStealth bot or self-built agentAssess like any bot

How AI agent verification works

Two methods exist today. The first is stronger; the second is a useful fallback.

  1. 01

    The agent signs each request

    With Web Bot Auth, built on the HTTP Message Signatures standard (RFC 9421), the agent attaches a signature made with its operator's private key, plus a header naming the operator's key directory.

  2. 02

    The site fetches the public key

    Operators publish their public keys at a well-known address on their own domain. OpenAI, for example, publishes the keys for its ChatGPT agents on chatgpt.com.

  3. 03

    The signature is checked

    If the signature matches the key and falls inside its short validity window, the request really came from that operator. A copied header on a different request does not pass.

  4. 04

    IP ranges back it up

    Many operators also publish the IP ranges their agents and crawlers use. A declared agent coming from inside those ranges is likely genuine; one from outside is unverified.

  5. 05

    Your policy decides

    Verification answers "who is this?" It does not answer "should it be here?" That part is your call, per project and per endpoint.

Agentic commerce: an opportunity, not only a threat

Shoppers are starting to hand errands to agents: find these running shoes in my size under a set price, rebook this flight, reorder the usual groceries. Payment networks are preparing for it. Visa introduced its Trusted Agent Protocol in October 2025, and Mastercard, which announced Agent Pay in April 2025, said the same month that it is incorporating Web Bot Auth into Agent Pay, so merchants can recognize trusted shopping agents by the same signatures.

Blocking every agent means turning away customers who chose to shop this way. Letting every agent in means letting in anything that calls itself one. The workable middle is to recognize verified agents, give them a clear path through product pages and checkout, and apply the same fraud checks you would apply to the person they act for.

How agents get abused

The same abilities that make agents useful make them attractive to fraudsters.

  • Borrowed identities

    Scrapers and bots copy the name of a well-known agent or crawler, hoping sites that trust the label will wave them through.

  • Scraping at agent scale

    Self-built agents read prices, stock and content page by page, a new flavor of web scraping that looks like browsing.

  • Bulk signups and trials

    Frameworks fill signup forms, read verification emails and claim free credits, feeding free-trial abuse in SaaS and AI products.

  • Buying up inventory

    Agents told to "get two tickets the second sales open" act faster than people, which edges into scalping.

  • Stealth automation

    Undeclared agents run on headless browsers with stealth plugins and residential proxies, and never say what they are.

  • Actions inside real accounts

    An agent working in a customer's logged-in session can look like a takeover: new device, new network. Verification separates the two.

Choosing a policy: allow, check or block

Agent policy is a business decision, and it differs by page. A retailer may welcome shopping agents on product pages and checkout but not on the gift card balance page. A publisher may allow agents that fetch one article for a reader and block bulk collection. A sportsbook may block agents entirely on bet placement.

Set a default per category, then refine per endpoint: allow verified agents where they bring customers, check unverified ones with rate limits or an invisible challenge, and block impostors everywhere. Review the numbers in observe-only mode before switching anything to block.

  • Allow: verified agents on browsing, search, cart and checkout, with normal payment and account checks still applied.
  • Check: declared but unverified agents, and verified agents on sensitive actions such as password changes or payouts.
  • Block: impostors, and any automation, declared or not, on endpoints you reserve for people.

Watch for false positives in both directions. A verified agent working in a customer's account will often show a new device and a new network, which a plain login rule reads as a takeover. An agentic browser on the customer's own laptop may look almost exactly like the customer. Tie agent verdicts to the account's history, so the same person using a new tool is not treated as a stranger.

A verified agent vs an impostor

Verified agent

  • Valid signature from the operator's published key
  • Connects from the operator's published ranges
  • Declares itself openly and behaves like an agent
  • Acts within a session the customer started

Impostor

  • Claims a trusted name with no signature or a broken one
  • Comes from a proxy pool or an unrelated host
  • Hides automation behind stealth plugins
  • Hits signups, prices or stock at bot speed

Sources

  1. Mastercard: Mastercard unveils Agent Pay (April 29, 2025)
  2. Cloudflare: Securing agentic commerce with Visa and Mastercard (October 2025)
  3. IETF RFC 9421: HTTP Message Signatures
  4. IETF Web Bot Auth working group: HTTP Message Signatures for automated traffic (draft-ietf-webbotauth-httpsig-protocol)
  5. OpenAI: Overview of OpenAI crawlers and agents, with published IP ranges
  6. Visa: Visa Introduces Trusted Agent Protocol (October 14, 2025)

How Kavra helps

How Kavra handles AI agents

Kavra identifies who is on the other end, a person, a bot, an AI agent or a tool pretending to be a browser, and lets you decide what each may do.

  • Cryptographic verification

    Verified search crawlers and AI agents, such as OpenAI's ChatGPT agents, are recognized by their cryptographic signatures and their operators' published IP ranges.

  • Unverified claims flagged

    A declared bot or agent outside its operator's ranges, or without a valid signature, is flagged as unverified instead of trusted by name.

  • Undeclared automation caught

    Stealth agents on headless browsers and proxies are assessed across 3,000+ data points, looking for contradictions between what they claim and how they behave.

  • Allow, check or block per project

    Set agent policy for each project, and let your backend apply it per endpoint. Kavra recommends; your backend decides.

  • Fraud checks still apply

    A verified agent in a customer's session still gets account, payment and device checks, so trust in the operator never replaces trust in the account.

  • Explained in the console

    Every assessment names the agent, how it was verified and why, with network context. Start in observe-only mode to see agent traffic first.

FAQ

Frequently asked questions

Something else? Talk to our team.

Should I block AI agents on my website?

Usually not all of them. Verified agents acting for real customers can bring sales, bookings and signups, so blocking them turns away buyers. A better approach is to allow verified agents where they help, check unverified ones with rate limits or challenges, and block impostors and undeclared automation on sensitive endpoints.

What is Web Bot Auth?

Web Bot Auth is an emerging standard that lets bots and AI agents prove who they are. The agent signs each request with its operator's private key, using HTTP Message Signatures, and names where its public keys are published. The website checks the signature against those keys. A valid signature shows the request came from that operator.

How can I tell if a visitor is an OpenAI agent?

OpenAI's ChatGPT agents sign their requests with Web Bot Auth, naming chatgpt.com as the signer, and OpenAI publishes the public keys and IP ranges it uses. Checking the signature, and the IP as a fallback, confirms it. A visitor that only claims to be ChatGPT in its user agent, with no valid signature, should be treated as unverified.

Can agentic browsers like Perplexity Comet be detected?

Agentic browsers run on the user's own computer inside a real browser, so their traffic can look like the user's. They can often be recognized by how the page is driven, such as timing and interaction patterns, and by any identity the browser declares. The fair response is usually to treat them like the user, with normal fraud checks.

What is the difference between an AI agent and a web crawler?

A crawler reads pages to build a search index or train a model, usually without logging in or taking actions. An AI agent performs tasks for a specific person: it fills forms, signs in, adds to cart and checks out. Crawlers affect content and load; agents touch accounts, payments and inventory, so they need finer policies.

Can someone fake being a verified AI agent?

They can copy an agent's name, but not its signature. A valid Web Bot Auth signature requires the operator's private key, and a declared agent connecting from outside its operator's published IP ranges stands out. Kavra flags these claims as unverified or impostors, so a borrowed name does not earn trusted access.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.