Markdown Version | Transcript | Session Recording | Session Materials

Session Date/Time: 22 Jul 2026 07:00 ✎ Suggest a correction

WEBBOTAUTH

Summary

The WEBBOTAUTH Working Group met at IETF 126 in Vienna. Co-Chairs Raffat and David Schinazi presided. The session focused on the two parallel paths established at the April interim meeting for web bot authentication:

  1. Identifying Bot Authentication: Cryptographically identifying bots.
  2. Anonymous Bot Authentication: Demonstrating bot properties without revealing specific identity.

The group also discussed crawler best practices as an informational/operational item.


Key Discussion Points

1. HTTP Message Signatures for Automated Traffic

Thibault Meunier presented the individual draft on this topic.


2. Anonymous Bot Authentication

Eric Rescorla presented the anonymous authentication path, which relies heavily on the emerging "MOLE" (Modulated Oblivious Logarithmic Evaluation) architecture.


3. Crawler Best Practices

Gary Illyes presented on documenting the de facto operational conventions of web crawlers.


Decisions and Action Items

Polls

The chairs ran a single poll regarding the identifying approach ("HTTP Message Signatures for automated traffic") to gauge group consensus on the starting direction:

Actions


Next Steps

Related Documents

draft-farzdusa-webbot-datacollection, draft-ietf-wimse-workload-identity-practices-05