Google Cloud Google Cloud

Web Bot Authentication Demo

Service Extensions • HTTP Message Signatures
Load Balancer Ready

Step 1: Select Bot Traffic Scenario

Choose a bot identity to send signed HTTP requests to the Google Cloud Load Balancer

Legitimate Search / AI Bot Verified

Authentic search/crawler bot with valid Ed25519 signature & trusted JWKS key.

Ed25519 (OKP) JWKS Matched Valid Window
Malicious Impersonator Forged Sig

Rogue scraper spoofing official Googlebot User-Agent with invalid cryptographic signature.

Spoofed UA Crypto Fail
Expired Replay Bot Expired

Previously captured signature packet replayed past the HTTP Message Signatures validity window.

Replay Attack expires < now
Unsigned Legacy Scraper No Headers

Standard automated HTTP bot request missing required Web Bot Auth headers.

Unauthenticated No Sig-Agent

Step 2: Edge Processing Stages

Watch Google Cloud Service Extensions intercept, fetch JWKS, and verify signatures

Ready to Go
🤖
1. Incoming Bot Request
HTTP/2 Request with HTTP Message Signatures headers
Signature-Agent https://storage.googleapis.com/media-assets-public/.well-known/http-message-signature-directory Signature-Input sig1=("@method" "@path" "@authority");keyid="my-bot-key-1";alg="ed25519" Signature sig1=:a3F9xK2mP9vL1w8bQ==:
☁️
2. Google Cloud Load Balancer Intercept
Google Cloud Service Extensions
Translating HTTP/2 pseudo-headers (:method, :path, :authority)
🛡️
3. Cryptographic Signature Verifier
Reconstruct HTTP Message Signatures Section 2.5 Target Base String
Algorithm: Ed25519 (OKP) • KeyID: my-bot-key-1
⚖️
4. Policy Verdict & Header Mutation
Awaiting request trigger...
Standby

Step 3: Verifications and Results

Inspect edge decision (200 OK vs 403 Access Denied), Load Balancer Latency, and mutated HTTP headers

Authentication
Pending
HTTP Message Signatures Asymmetric Signature
Routing Policy
Standby
Google Cloud Service Extensions
Edge Latency
-- ms
Service Extension Callout RTT
// HTTP Response Body from Google Cloud Load Balancer / Backend
@method @path @authority @signature-params
// HTTP Message Signatures Section 2.5 Signature Base Target String will appear here after execution
Header Name Mutated Value injected by Service Extension
No request executed yet