{"uid":"cap_fF4EDRgA_J_cF81E-9js-","slug":"witness-holoweave-signature-acceptance-check-0196e7be","name":"Witness Holoweave Signature Acceptance Check","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/signature-acceptance","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"fail","endpoint":"signature-acceptance","evidence":{"acceptance":{"aws-waf":{"result":"unknown","reason_code":"FORM_RULES_UNSTATED"},"cloudflare":{"result":"reject","reason_code":"CF_SIG_AGENT_DICTIONARY_FORM"}}}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_EeOJFfk3KaX_WhhFOkSMq","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a signed HTTP request would be accepted by major bot-auth verifiers (Cloudflare, AWS WAF, Akamai, Vercel) according to the draft-meunier-web-bot-auth-architecture spec","exampleAgentPrompt":"Check whether my signed request to https://api.example.com/data — using these headers including Signature-Input and Signature — would be accepted by Cloudflare's bot-auth verifier according to the draft-meunier spec; my JWKS is at https://myagent.example.com/.well-known/jwks.json.","exampleUseCases":[{"title":"Pre-flight Cloudflare bot auth check","prompt":"Before I send my signed agent request to this Cloudflare-protected API, can you check if my Signature-Input and Signature headers would actually be accepted? My JWKS is at https://mybot.example.com/.well-known/jwks.json and I want to validate against Cloudflare."},{"title":"Multi-verifier acceptance audit","prompt":"I'm deploying my agent to talk to APIs behind different WAFs — can you check my signed request headers against Cloudflare, AWS WAF, and Akamai to see which ones would accept or reject my bot-auth signature?"},{"title":"Debug failing bot-auth signature","prompt":"My agent keeps getting blocked when hitting Vercel-protected endpoints. Can you judge whether my Signature-Input, Signature, and Signature-Agent headers are correctly formed for the draft-meunier-web-bot-auth-architecture spec?"}],"resultDescription":"A per-verifier acceptance verdict indicating whether the signed request would pass bot-auth checks on each requested platform (Cloudflare, AWS WAF, Akamai, Vercel). Cloudflare provides form-level rule detail; others return 'unknown' if rules aren't published. Includes overall compliance status against the draft-meunier-web-bot-auth-architecture spec.","failureModes":["Missing required headers (Signature-Input, Signature) returns validation error","Invalid JWKS URI or unreachable key directory causes key lookup failure","Unsupported verifier name returns error or unknown verdict","Malformed request_sample object causes schema validation rejection","Network issues reaching verifier endpoints may return partial results"],"whenToPreferThis":"Use this endpoint when you need to pre-flight check whether an agent's signed HTTP request will be accepted by specific deployed WAF/bot-auth verifiers before actually sending it. It is purpose-built for the draft-meunier-web-bot-auth-architecture spec and tests against real verifier rule sets (especially Cloudflare). Prefer this over generic signature validators when you specifically need per-verifier acceptance decisions, not just cryptographic correctness — for that, use the sibling RFC 9421 signature verification endpoint instead.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:26:06.077Z","isFirstParty":false}