Web Bot Auth broken variant
A JWKS at /.well-known/http-message-signatures-directory publishing usable public verification keys.
Site-wide file — one per host.
This signal isn't a page; the container fetches it at a fixed path, and the
correct/broken/authbroken variant is chosen by the request host. On this host the canonical path(s)
below serve the broken variant. Add
?mode=… to override locally.
Canonical path(s)
Broken variant
The listed Ed25519 key has a too-short x, so no usable verification key is published.
Catalogued flags
| Flag | Kind | Severity |
|---|---|---|
webBotAuthMalformedDirectory | defect | high |
webBotAuthMissingKeys | defect | high |
webBotAuthInvalidKey | defect | high |
webBotAuthPrivateKeyExposed | defect | high |
webBotAuthWrongMediaType | defect | medium |
Fetch the live file: https://agentic-mcp-strict.crawler-test.com/.well-known/http-message-signatures-directory