Overview
Google-Agent Web Bot Auth is a signed agent associated with Google, used for cryptographically authenticating a subset of Google-Agent requests through experimental Web Bot Auth.
Related signed-identity indicators include Google-Agent signed identity; https://agent.bot.goog.
Google-Agent Web Bot Auth is verified with High confidence. The identity type is Signed Agent.
Google-Agent Web Bot Auth may ignore robots.txt because the request is user-triggered, signed, or otherwise outside normal autonomous crawler behavior. Use authenticated access controls or network policy when enforcement is required.
The signed request identity is not a separate fixed user-agent token.
Treat the user-agent or identity as a claim and corroborate it with published network data, reverse DNS, signed-request evidence, or current operator documentation when available.
Identity
- Aliases
- Google-Agent signed identity; https://agent.bot.goog
- HTTP Agent Examples
-
No fixed HTTP User-Agent for the signed identity; verify Web Bot Auth identity `https://agent.bot.goog`. - Identity Type
- Signed agent
- Evidence Method
- Verify Google-Agent Web Bot Auth by matching the documented signed-request identity to Google evidence, then corroborating the request with source-network ownership, reverse DNS, signed request data, or current operator documentation.
Classification
- Type
- AI
- Kind
- Signed agent
- Family
- Google-Agent
- Purpose
- Authenticated user-triggered agent
Behavior and handling
- Common Use
- cryptographically authenticating a subset of Google-Agent requests through experimental Web Bot Auth
- Detection Notes
- Google-Agent Web Bot Auth traffic is primarily detected by its documented signed-request identity; related patterns include `Google-Agent signed identity; https://agent.bot.goog`. Treat these values as identification claims and corroborate them with source-network ownership, reverse DNS, signed request data, or current operator documentation.
- Respects robots.txt
- No
- Spoofing Risk
- Low when the Web Bot Auth signature for `https://agent.bot.goog` is cryptographically validated; an unsigned copied label is not trustworthy.
- Risk
- Safe
- Recommended Handling
- Depends
Rules and controls
- Robots.txt Snippet
-
# No fixed robots.txt token. Verify the signed request identity instead.
Relationships
- Operator
- Google Checked 2026-08-07
Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.