@techreport{ietf-webbotauth-httpsig-protocol-00, number = {draft-ietf-webbotauth-httpsig-protocol-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/00/}, author = {Thibault Meunier and Sandor Major}, title = {{HTTP Message Signatures for automated traffic}}, pagetotal = 44, year = 2026, month = sep, day = 1, abstract = {This document describes a protocol for identifying automated traffic using {[}HTTP-MESSAGE-SIGNATURES{]}. The goal is to allow automated HTTP clients to cryptographically sign outbound requests, allowing HTTP servers to verify their identity with confidence. It defines the Signature-Agent header field for in-band key discovery, a key directory format based on JWKS, and a well-known URI at which that directory is served.}, }