# Web Bot Auth implementation check — wba.cloudless.sh > Send a live Web Bot Auth signed request and get a step-by-step report of whether it verifies against your own published key directory, and if not, where it fails. A public Web Bot Auth (RFC 9421 HTTP Message Signatures, web-bot-auth profile) implementation check. It is open-world: any agent whose key directory is reachable over HTTPS can be verified, with no registration. A verified result means the signature verified against the agent's own published directory at that time — nothing more. It does not certify, list, trust, or admit agents. ## Endpoint - [GET /v1/whoami](https://wba.cloudless.sh/v1/whoami): send a request signed with the web-bot-auth profile (draft-ietf-webbotauth-httpsig-protocol-00). Returns a JSON report (schema cloudless.wba_whoami.v1). Required: Signature-Agent pointing at your directory origin; Signature-Input covering @target-uri (or @authority) and signature-agent, with tag="web-bot-auth", keyid = RFC 7638 JWK thumbprint, created, expires, and a nonce; max age 60 s, clock skew 5 s. Sign the exact URL https://wba.cloudless.sh/v1/whoami (query included). ## Verdicts - verified (HTTP 200): The signature and key material validate, and every policy check passed. - invalid (HTTP 401): The signature, covered components, key, or freshness checks fail. - unverified (HTTP 401): Not enough information to decide — no signature headers, the directory could not be fetched or parsed, or the key is not in it. - Other statuses: 405 for methods other than GET/HEAD, 429 when rate-limited. ## Report steps (in order) - headers: Signature-Input, Signature and Signature-Agent are present and parse as structured fields. - signature_agent: Dictionary form (sig1="https://…") or the legacy bare string; an HTTPS origin on the default port. The report says which form you sent. - directory_fetch: GET /.well-known/http-message-signatures-directory on that origin: status, content type, size (64 KB cap), no redirects, timing, and whether the result came from cache. - directory_key: The keyid is in the directory, matched by RFC 7638 thumbprint (or kid), and is an Ed25519 key. - directory_signature: If the directory response is signed (RECOMMENDED by the draft's Appendix B.1), the signature is validated. Absent or invalid is a warning, never a failure. - coverage: The signature covers @target-uri (or @authority) and signature-agent. - tag_alg: tag="web-bot-auth"; alg, if present, is ed25519. - freshness: created and expires are present and current against server time, within the max age and clock skew. - nonce: A nonce is present, well formed, and not replayed within the freshness window. - signature: The signature verifies over the reconstructed target. If only freshness failed, this still runs with the clock pinned to created, so you learn whether the signing itself is right. ## Demo identity To get a verified report without hosting a directory, sign with the RFC 9421 Appendix B.1.4 Ed25519 test key (https://www.rfc-editor.org/rfc/rfc9421#appendix-B.1.4), Signature-Agent: sig1="https://wba.cloudless.sh";type=directory, keyid poqkLGiymh_W0uP6PZFw-dvez3QJT5SolqXBCW38r0U. Its public key is published at https://wba.cloudless.sh/.well-known/http-message-signatures-directory. The key is public on purpose and identifies nobody. ## More - [Human page](https://wba.cloudless.sh/) - [OpenAPI](https://wba.cloudless.sh/openapi.json) - [draft-ietf-webbotauth-httpsig-protocol-00](https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/) - [RFC 9421](https://www.rfc-editor.org/rfc/rfc9421) - [Fingerprint — Web Bot Auth test endpoint](https://fingerprint.com/web-bot-auth/test/): send a live signed request; open source - [webbotauth.net](https://webbotauth.net/): directory grading and pasted-header verification - [verifyagents.org](https://verifyagents.org/): pasted-request and directory debugger