Back

WBA Signature Validator

Verify an HTTP Message Signature against RFC 9421 — the mechanism behind WebBot Auth

Parsed and, if you choose to verify, checked entirely in your browser using the Web Crypto API — the request is never sent to any server. Fetching a signer's key directory makes a direct browser fetch to that URL (not through our server). If the request has a Signature-Agent header (WBA's agent identity), it's detected and shown, including a check that it's actually covered by the signature. Currently supports the ed25519 algorithm only, and covered components that are plain header fields (optionally with a ;key dictionary-member selector), or the @method/@path/@query/@authority/@scheme/@target-uri/@request-target derived components — not structured-field (;sf), binary-wrapped (;bs), trailer (;tr), or @query-param component parameters, and not Inner-List-valued dictionary members.