Today, we’re excited to announce the addition of Web Bot Auth (WBA) support in AWS WAF, providing a secure and standardized way to authenticate legitimate AI agents and automated tools accessing web applications. This new capability helps distinguish trusted bot traffic from potentially harmful automated access attempts.
Web Bot Auth is an authentication method that leverages cryptographic signatures in HTTP messages to verifythat a request comes from an automated bot. Web Bot Auth is used as a verification method for verified bots and signed agents. It relies on two active IETF drafts: a directory draft allowing the crawler to share their public keys, and a protocol draft defining how these keys should be used to attach crawler’s identity to HTTP requests.
AWS WAF now automatically allows verified AI agent traffic Verified WBA bots will now be automatically allowed by default, previously Category AI blocked unverified bots, this behavior is now refined to respect WBA verification.
To learn more, please review the documentation.
Categories: marketing:marchitecture/security-identity-and-compliance,general:products/aws-waf
Source: Amazon Web Services

![Site attestation policy is now generally available [MC1198075] 2 pexels pachon in motion 426015731 18545013](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pachon-in-motion-426015731-18545013-150x150.webp)
![Updates available for Microsoft 365 Apps for Current Channel [MC1198067] 3 giraffe 5767909 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/giraffe-5767909_1920-150x150.webp)
![Microsoft Entra: Cross-tenant security group synchronization [MC1198077] 4 pexels alexasfotos 32112166](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-alexasfotos-32112166-150x150.webp)
![Migrate User Data Across Tenants: Mailboxes, OneDrives, and Teams Chats [MC1198079] 5 pexels pixabay 36753](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-pixabay-36753-150x150.webp)
