# AI agent detection that lets verified agents in and keeps impostors out

Source: https://kavralab.com/detect/ai-agents/

**AI agent detection** identifies software that browses and acts for a person, such as ChatGPT's cloud browser or an agentic browser, and checks whether it is who it claims to be. Verified agents prove identity with cryptographic signatures or their operator's published IP ranges. Kavra separates verified agents from unverified claims and impostors, and you choose allow, check or block.

- **Who it hits:** E-commerce, travel, SaaS, marketplaces, publishers
- **What is at stake:** Agent-driven sales on one side, abuse on the other
- **Agents seen:** Hosted agents, agentic browsers, open-source frameworks
- **Where to decide:** Per project, per agent, per endpoint

## What is an AI agent on your website?

An [AI agent](https://kavralab.com/glossary/ai-agent/) is software that uses a language model to carry out a task on the web for a person: search for a product, compare prices, fill a form, book a table or complete a checkout. Unlike a crawler that reads pages to build an index, an agent acts. It clicks, types, logs in and sometimes pays.

Agents reach your site in three main ways. **Hosted agents**, such as the cloud browser in OpenAI's ChatGPT or Google's Gemini agent, run a browser in the operator's cloud. **Agentic browsers**, such as Perplexity Comet, run on the user's own computer, inside a real browser, next to the user's own tabs. **Open-source frameworks** in the style of browser-use let anyone wire a model to an automated browser and point it at any site, for any purpose.

## Verified, unverified and impostor agents

The name an agent gives is a claim, not proof. Sort agent traffic by what it can prove.

| Type | What you see | What it means | Sensible default |
|---|---|---|---|
| Verified agent | A declared agent with a valid cryptographic signature, or an IP inside the operator's published ranges | The operator stands behind the request | Allow, with limits you set |
| Declared but unverified | Says it is an agent, but offers no signature and comes from outside known ranges | Could be honest but unsigned, or a copy of the name | Check: rate-limit or challenge |
| Impostor | Claims a known agent or crawler name, but the signature fails or the IP belongs to someone else | Someone is borrowing a trusted name | Block |
| Undeclared automation | Looks like a person in a normal browser, but behaves like software | Stealth bot or self-built agent | Assess like any bot |

## How AI agent verification works

Two methods exist today. The first is stronger; the second is a useful fallback.

1. **The agent signs each request**: With **Web Bot Auth**, built on the HTTP Message Signatures standard (RFC 9421), the agent attaches a signature made with its operator's private key, plus a header naming the operator's key directory.
2. **The site fetches the public key**: Operators publish their public keys at a well-known address on their own domain. OpenAI, for example, publishes the keys for its ChatGPT agents on chatgpt.com.
3. **The signature is checked**: If the signature matches the key and falls inside its short validity window, the request really came from that operator. A copied header on a different request does not pass.
4. **IP ranges back it up**: Many operators also publish the IP ranges their agents and crawlers use. A declared agent coming from inside those ranges is likely genuine; one from outside is unverified.
5. **Your policy decides**: Verification answers "who is this?" It does not answer "should it be here?" That part is your call, per project and per endpoint.

## Agentic commerce: an opportunity, not only a threat

Shoppers are starting to hand errands to agents: find these running shoes in my size under a set price, rebook this flight, reorder the usual groceries. Payment networks are preparing for it. Visa introduced its Trusted Agent Protocol in October 2025, and Mastercard, which announced Agent Pay in April 2025, said the same month that it is incorporating Web Bot Auth into Agent Pay, so merchants can recognize trusted shopping agents by the same signatures.

Blocking every agent means turning away customers who chose to shop this way. Letting every agent in means letting in anything that calls itself one. The workable middle is to recognize verified agents, give them a clear path through product pages and checkout, and apply the same fraud checks you would apply to the person they act for.

## How agents get abused

The same abilities that make agents useful make them attractive to fraudsters.

- **Borrowed identities**: Scrapers and bots copy the name of a well-known agent or crawler, hoping sites that trust the label will wave them through.
- **Scraping at agent scale**: Self-built agents read prices, stock and content page by page, a new flavor of [web scraping](https://kavralab.com/solutions/web-scraping/) that looks like browsing.
- **Bulk signups and trials**: Frameworks fill signup forms, read verification emails and claim free credits, feeding [free-trial abuse](https://kavralab.com/solutions/free-trial-abuse/) in SaaS and AI products.
- **Buying up inventory**: Agents told to "get two tickets the second sales open" act faster than people, which edges into [scalping](https://kavralab.com/solutions/scalping/).
- **Stealth automation**: Undeclared agents run on [headless browsers](https://kavralab.com/detect/headless-browsers/) with stealth plugins and residential proxies, and never say what they are.
- **Actions inside real accounts**: An agent working in a customer's logged-in session can look like a takeover: new device, new network. Verification separates the two.

## Choosing a policy: allow, check or block

Agent policy is a business decision, and it differs by page. A retailer may welcome shopping agents on product pages and checkout but not on the gift card balance page. A publisher may allow agents that fetch one article for a reader and block bulk collection. A sportsbook may block agents entirely on bet placement.

Set a default per category, then refine per endpoint: allow verified agents where they bring customers, check unverified ones with rate limits or an invisible challenge, and block impostors everywhere. Review the numbers in [observe-only mode](https://kavralab.com/integrations/) before switching anything to block.

- **Allow**: verified agents on browsing, search, cart and checkout, with normal payment and account checks still applied.
- **Check**: declared but unverified agents, and verified agents on sensitive actions such as password changes or payouts.
- **Block**: impostors, and any automation, declared or not, on endpoints you reserve for people.

Watch for false positives in both directions. A verified agent working in a customer's account will often show a new device and a new network, which a plain login rule reads as a takeover. An agentic browser on the customer's own laptop may look almost exactly like the customer. Tie agent verdicts to the account's history, so the same person using a new tool is not treated as a stranger.

## A verified agent vs an impostor

**Verified agent**

- Valid signature from the operator's published key
- Connects from the operator's published ranges
- Declares itself openly and behaves like an agent
- Acts within a session the customer started

**Impostor**

- Claims a trusted name with no signature or a broken one
- Comes from a proxy pool or an unrelated host
- Hides automation behind stealth plugins
- Hits signups, prices or stock at bot speed

> **Key takeaway:** Do not ask "is this a bot?" and stop there. Ask **which** agent it is, whether it can prove it, and what you want it to do on this page. Verified agents are customers in a new form; impostors are bots in a borrowed coat. Read how [good bots](https://kavralab.com/glossary/good-bot/) differ from bad ones, and how agents change [e-commerce](https://kavralab.com/industries/ecommerce/).

## How Kavra handles AI agents

Kavra identifies who is on the other end, a person, a bot, an AI agent or a tool pretending to be a browser, and lets you decide what each may do.

- **Cryptographic verification**: Verified search crawlers and AI agents, such as OpenAI's ChatGPT agents, are recognized by their cryptographic signatures and their operators' published IP ranges.
- **Unverified claims flagged**: A declared bot or agent outside its operator's ranges, or without a valid signature, is flagged as unverified instead of trusted by name.
- **Undeclared automation caught**: Stealth agents on headless browsers and proxies are assessed across 3,000+ data points, looking for contradictions between what they claim and how they behave.
- **Allow, check or block per project**: Set agent policy for each project, and let your backend apply it per endpoint. Kavra recommends; your backend decides.
- **Fraud checks still apply**: A verified agent in a customer's session still gets account, payment and device checks, so trust in the operator never replaces trust in the account.
- **Explained in the console**: Every assessment names the agent, how it was verified and why, with network context. Start in observe-only mode to see agent traffic first.

## FAQ

### Should I block AI agents on my website?

Usually not all of them. Verified agents acting for real customers can bring sales, bookings and signups, so blocking them turns away buyers. A better approach is to allow verified agents where they help, check unverified ones with rate limits or challenges, and block impostors and undeclared automation on sensitive endpoints.

### What is Web Bot Auth?

Web Bot Auth is an emerging standard that lets bots and AI agents prove who they are. The agent signs each request with its operator's private key, using HTTP Message Signatures, and names where its public keys are published. The website checks the signature against those keys. A valid signature shows the request came from that operator.

### How can I tell if a visitor is an OpenAI agent?

OpenAI's ChatGPT agents sign their requests with Web Bot Auth, naming chatgpt.com as the signer, and OpenAI publishes the public keys and IP ranges it uses. Checking the signature, and the IP as a fallback, confirms it. A visitor that only claims to be ChatGPT in its user agent, with no valid signature, should be treated as unverified.

### Can agentic browsers like Perplexity Comet be detected?

Agentic browsers run on the user's own computer inside a real browser, so their traffic can look like the user's. They can often be recognized by how the page is driven, such as timing and interaction patterns, and by any identity the browser declares. The fair response is usually to treat them like the user, with normal fraud checks.

### What is the difference between an AI agent and a web crawler?

A crawler reads pages to build a search index or train a model, usually without logging in or taking actions. An AI agent performs tasks for a specific person: it fills forms, signs in, adds to cart and checks out. Crawlers affect content and load; agents touch accounts, payments and inventory, so they need finer policies.

### Can someone fake being a verified AI agent?

They can copy an agent's name, but not its signature. A valid Web Bot Auth signature requires the operator's private key, and a declared agent connecting from outside its operator's published IP ranges stands out. Kavra flags these claims as unverified or impostors, so a borrowed name does not earn trusted access.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
