Authenticate legitimate AI agent traffic with AWS WAF Bot Control
Security Blog
This article explains how Web Bot Authentication (WBA) in AWS WAF Bot Control uses cryptographic signatures to verify legitimate AI agent traffic and prevent spoofing attacks.
- WBA uses asymmetric cryptography and IETF standards to verify bot identities through HTTP message signatures
- AWS WAF automatically allows verified AI agent traffic and applies labels for granular control (verified, invalid, expired, unknown_bot)
- Solves multi-tenant IP-sharing challenges where traditional IP filtering and allowlists fail
- Bot Control rule group Version 4.0+ supports WBA for CloudFront; Version 6.0 extends to all AWS WAF resource types
- Enables use cases: verified customer support agents, search engine crawlers, partner integrations, and enterprise automation tools
- Agents on Amazon Bedrock AgentCore Browser get automatic request signing; others can implement signing via ed25519 key pairs
WBA provides cryptographically secure, standards-based bot authentication that reduces false positives and improves visibility into automated traffic across shared infrastructure.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Aug 1
2025
2025
How to manage AI Bots with AWS WAF and enhance security
Feb 25
2026
2026
AWS WAF announces AI activity dashboard for visibility into AI bot and agent traffic
Mar 7
2025
2025
How to use AWS WAF Bot Control for Targeted Bots signals and mitigate evasive bots with adaptive user experience
Jul 15
2024
2024
Protect against bots with AWS WAF Challenge and CAPTCHA actions
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.