Overview
Drift Agent is a signed automated agent associated with Drift Security.
No fixed HTTP User-Agent is published for this identity. Verify it using cryptographic HTTP Message Signatures, published key material, and supporting request context rather than a copied user-agent string.
Botcrawl records this identity as a signed-agent with High confidence.
Identity
- Aliases
- drift-agent; Signature-Agent key directory: https://api.driftsecurity.ai/.well-known/http-message-signatures-directory
- HTTP Agent Examples
No fixed HTTP user-agent published; use signed-agent identity and supporting request headers.- Identity Type
- Signed Agent
- Evidence Method
- Verify Drift Agent using cryptographic HTTP Message Signatures and the agent’s published key material. Reject unsigned, invalidly signed, or unverifiable requests as authenticated identity claims.
Classification
- Type
- AI
- Kind
- Agent
- Family
- Drift Agent
- Purpose
- Security Automation
Behavior and handling
- Common Use
- Drift Agent is used for AI crawler discovery, assistant retrieval, AI search support, or model-related web access.
- Detection Notes
- Drift Agent should be identified through cryptographic HTTP Message Signatures and published key material. Do not treat a matching browser string, slug, or arbitrary User-Agent value as proof of identity.
- Respects robots.txt
- Unknown
- Spoofing Risk
- Drift Agent can be impersonated by name in unsigned traffic. Treat the identity as trusted only when cryptographic signature verification succeeds against published key material.
- Risk
- Neutral
- Recommended Handling
- Depends
Rules and controls
- Robots.txt Snippet
# No fixed robots.txt token. Verify the signed request identity instead.