Authenticate legitimate AI agent traffic with AWS WAF Bot Control
July 14, 2026 · AWS Security · Severity: CRITICAL
As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedrock AgentCore ) where thousands of distinct workloads share the same IP space.
As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedrock AgentCore) where thousands of distinct workloads share the same IP space. Attackers can easily spoof user agents, and manual allowlists don’t scale with growing demand.
Web Bot Authentication (WBA), available in AWS WAF Bot Control since November 2025, solves this challenge by implementing cryptographic signatures that provide tamper-proof verification of bot identities. WBA uses asymmetric cryptography to verify that a request comes from an authorized automated agent, relying on two active Internet Engineering Task Force (IETF) drafts: a directory draft for sharing public keys, and a protocol draft defining how keys attach crawler identity to HTTP requests.
With WBA, you can confidently identify trusted automated access while maintaining granular control through WAF labels, creating a more secure and manageable ecosystem for both bot operators and website owners. AWS WAF Bot Control respects WBA verification status by default, automatically allowing verified AI agent traffic.
This post provides a deeper technical guide to implementing WBA with AWS WAF. You learn how WBA works, explore the new labels and capabilities it introduces, and walk through a step-by-step implementation—including signing code—to authenticate bot traffic using cryptographic signatures.
How Web Bot Authentication works with AWS WAF
WBA uses asymmetric cryptography to verify bot identities through HTTP message signatures. The process works as follows:
- Bot registration – Bot operators publish their public keys in a signature directory. AWS WAF regularly polls these directories and maintains a valid key registry.
- Request signing – Each bot operator’s request is signed using their private key following the IETF standard HTTP Message Signatures (RFC 9421).
- Verification – AWS WAF verifies signatures against known public keys associated with the bot operator and appends labels related to verification status.
A typical WBA-signed request includes headers like the following:
The following sequence diagram shows how AWS WAF verifies bot signatures and applies labels for allow or block decisions.
Figure 1 – AWS WAF Web Bot Authentication verification flow
The workflow shown in figure 1 includes the following steps:
- A bot sends a signed request to Amazon CloudFront and is inspected by AWS WAF Bot Control
- AWS WAF Bot Control retrieves the bot operator’s public key from the signature directory
- AWS WAF Bot Control verifies the ed25519 signature
- AWS WAF Bot Control appends a verification label (
verified,invalid,expired, orunknown_bot)
AWS WAF Bot Control evaluates rules using the label to allow or block the request.
New capabilities added to AWS WAF
With the addition of WBA, the following capabilities were added to AWS WAF.
Cryptographic bot verification
When a bot sends a request, it includes HTTP message signatures that AWS WAF validates at the edge using the AWS WAF Bot Control rule group (version 4.0 and later). This validation process adds minimal latency to requests while providing cryptographic certainty about the bot’s identity. HTTP Message Signatures is an open IETF standard (RFC 9421) that defines a mechanism for signing and verifying HTTP messages using asymmetric keys—in practice, this means a bot cryptographically signs specific headers and metadata of each request, and the receiver can verify the signature using the bot’s published public key.
New labels within AWS WAF for granular control
AWS WAF automatically validates signatures, and successfully validated traffic is immediately marked as verified. This verification status can be used in WAF rules and bot management policies, giving you the ability to write your own rules based on the new functionality.
The following table describes the new labels.
| Label | Meaning | Suggested action |
| awswaf:managed:aws:bot-control:bot:web_bot_auth:verified | Successful cryptographic verification | Allow |
| awswaf:managed:aws:bot-control:bot:web_bot_auth:invalid | Failed verification attempt | Block or rate-limit |
| awswaf:managed:aws:bot-control:bot:web_bot_auth:expired | Expired key used | Block and alert |
| awswaf:managed:aws:bot-control:bot:web_bot_auth:unknown_bot | Unrecognized key | Monitor or block |
| awswaf:managed:aws:bot-control:bot:vendor:<vendor_name> | Bot vendor or operator | Use for vendor-specific rules |
| awswaf:managed:aws:bot-control:bot:name:<rfc_name> | Bot name (RFC token from WBA) | Use for bot-specific rules |
| awswaf:managed:aws:bot-control:bot:account:<hash> | AWS account identifier (Amazon Bedrock AgentCore agents only) | Use for account-level controls |
AWS WAF now automatically allows verified AI agent traffic
AWS WAF Bot Control now respects WBA verification status by default, automatically allowing verified AI agent traffic. This includes two specific behavior changes:
- Category:AI rule update – Previously, the
Category:AIrule under common Bot Control blocked unverified bots. Bot Control now checks WBA verification status before applying this rule. - TGT_TokenAbsent rule update – The
TGT_TokenAbsentrule, which detects requests without a WAF token, no longer matches requests that carry theweb_bot_auth:verifiedlabel.
Key benefits for AWS WAF customers
WBA with AWS WAF delivers several advantages for organizations managing automated traffic at scale.
- Enhanced bot visibility – Clear identification of distinct bots operating from multi-tenant platforms like Amazon Bedrock AgentCore, providing transparency into automated traffic sources. The AWS WAF console includes a
Key Takeaways
- AWS WAF Bot Control authenticates legitimate AI agent traffic effectively.
- Traditional IP filtering fails in multi-tenant systems against bot threats.
- Distinguishing legitimate bots from malicious ones is now critical for security.