POST /checkoutAllowedVerified OpenAI agent, signed
- Valid Web Bot Auth signature
- IP in operator's published range
- Acting in a known customer session
Detection
AI agent detection identifies software that browses and acts for a person, such as ChatGPT's cloud browser or an agentic browser, and checks whether it is who it claims to be. Verified agents prove identity with cryptographic signatures or their operator's published IP ranges. Kavra separates verified agents from unverified claims and impostors, and you choose allow, check or block.
POST /checkoutAllowedVerified OpenAI agent, signed
An AI agent is software that uses a language model to carry out a task on the web for a person: search for a product, compare prices, fill a form, book a table or complete a checkout. Unlike a crawler that reads pages to build an index, an agent acts. It clicks, types, logs in and sometimes pays.
Agents reach your site in three main ways. Hosted agents, such as the cloud browser in OpenAI's ChatGPT or Google's Gemini agent, run a browser in the operator's cloud. Agentic browsers, such as Perplexity Comet, run on the user's own computer, inside a real browser, next to the user's own tabs. Open-source frameworks in the style of browser-use let anyone wire a model to an automated browser and point it at any site, for any purpose.
The name an agent gives is a claim, not proof. Sort agent traffic by what it can prove.
| Type | What you see | What it means | Sensible default |
|---|---|---|---|
| Verified agent | A declared agent with a valid cryptographic signature, or an IP inside the operator's published ranges | The operator stands behind the request | Allow, with limits you set |
| Declared but unverified | Says it is an agent, but offers no signature and comes from outside known ranges | Could be honest but unsigned, or a copy of the name | Check: rate-limit or challenge |
| Impostor | Claims a known agent or crawler name, but the signature fails or the IP belongs to someone else | Someone is borrowing a trusted name | Block |
| Undeclared automation | Looks like a person in a normal browser, but behaves like software | Stealth bot or self-built agent | Assess like any bot |
Two methods exist today. The first is stronger; the second is a useful fallback.
With Web Bot Auth, built on the HTTP Message Signatures standard (RFC 9421), the agent attaches a signature made with its operator's private key, plus a header naming the operator's key directory.
Operators publish their public keys at a well-known address on their own domain. OpenAI, for example, publishes the keys for its ChatGPT agents on chatgpt.com.
If the signature matches the key and falls inside its short validity window, the request really came from that operator. A copied header on a different request does not pass.
Many operators also publish the IP ranges their agents and crawlers use. A declared agent coming from inside those ranges is likely genuine; one from outside is unverified.
Verification answers "who is this?" It does not answer "should it be here?" That part is your call, per project and per endpoint.
Shoppers are starting to hand errands to agents: find these running shoes in my size under a set price, rebook this flight, reorder the usual groceries. Payment networks are preparing for it. Visa introduced its Trusted Agent Protocol in October 2025, and Mastercard, which announced Agent Pay in April 2025, said the same month that it is incorporating Web Bot Auth into Agent Pay, so merchants can recognize trusted shopping agents by the same signatures.
Blocking every agent means turning away customers who chose to shop this way. Letting every agent in means letting in anything that calls itself one. The workable middle is to recognize verified agents, give them a clear path through product pages and checkout, and apply the same fraud checks you would apply to the person they act for.
The same abilities that make agents useful make them attractive to fraudsters.
Scrapers and bots copy the name of a well-known agent or crawler, hoping sites that trust the label will wave them through.
Self-built agents read prices, stock and content page by page, a new flavor of web scraping that looks like browsing.
Frameworks fill signup forms, read verification emails and claim free credits, feeding free-trial abuse in SaaS and AI products.
Agents told to "get two tickets the second sales open" act faster than people, which edges into scalping.
Undeclared agents run on headless browsers with stealth plugins and residential proxies, and never say what they are.
An agent working in a customer's logged-in session can look like a takeover: new device, new network. Verification separates the two.
Agent policy is a business decision, and it differs by page. A retailer may welcome shopping agents on product pages and checkout but not on the gift card balance page. A publisher may allow agents that fetch one article for a reader and block bulk collection. A sportsbook may block agents entirely on bet placement.
Set a default per category, then refine per endpoint: allow verified agents where they bring customers, check unverified ones with rate limits or an invisible challenge, and block impostors everywhere. Review the numbers in observe-only mode before switching anything to block.
Watch for false positives in both directions. A verified agent working in a customer's account will often show a new device and a new network, which a plain login rule reads as a takeover. An agentic browser on the customer's own laptop may look almost exactly like the customer. Tie agent verdicts to the account's history, so the same person using a new tool is not treated as a stranger.
How Kavra helps
Kavra identifies who is on the other end, a person, a bot, an AI agent or a tool pretending to be a browser, and lets you decide what each may do.
Verified search crawlers and AI agents, such as OpenAI's ChatGPT agents, are recognized by their cryptographic signatures and their operators' published IP ranges.
A declared bot or agent outside its operator's ranges, or without a valid signature, is flagged as unverified instead of trusted by name.
Stealth agents on headless browsers and proxies are assessed across 3,000+ data points, looking for contradictions between what they claim and how they behave.
Set agent policy for each project, and let your backend apply it per endpoint. Kavra recommends; your backend decides.
A verified agent in a customer's session still gets account, payment and device checks, so trust in the operator never replaces trust in the account.
Every assessment names the agent, how it was verified and why, with network context. Start in observe-only mode to see agent traffic first.
FAQ
Something else? Talk to our team.
Usually not all of them. Verified agents acting for real customers can bring sales, bookings and signups, so blocking them turns away buyers. A better approach is to allow verified agents where they help, check unverified ones with rate limits or challenges, and block impostors and undeclared automation on sensitive endpoints.
Web Bot Auth is an emerging standard that lets bots and AI agents prove who they are. The agent signs each request with its operator's private key, using HTTP Message Signatures, and names where its public keys are published. The website checks the signature against those keys. A valid signature shows the request came from that operator.
OpenAI's ChatGPT agents sign their requests with Web Bot Auth, naming chatgpt.com as the signer, and OpenAI publishes the public keys and IP ranges it uses. Checking the signature, and the IP as a fallback, confirms it. A visitor that only claims to be ChatGPT in its user agent, with no valid signature, should be treated as unverified.
Agentic browsers run on the user's own computer inside a real browser, so their traffic can look like the user's. They can often be recognized by how the page is driven, such as timing and interaction patterns, and by any identity the browser declares. The fair response is usually to treat them like the user, with normal fraud checks.
A crawler reads pages to build a search index or train a model, usually without logging in or taking actions. An AI agent performs tasks for a specific person: it fills forms, signs in, adds to cart and checks out. Crawlers affect content and load; agents touch accounts, payments and inventory, so they need finer policies.
They can copy an agent's name, but not its signature. A valid Web Bot Auth signature requires the operator's private key, and a declared agent connecting from outside its operator's published IP ranges stands out. Kavra flags these claims as unverified or impostors, so a borrowed name does not earn trusted access.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.