Skip to content

Commit ab38f98

Browse files
Drop --url param from web-bot-auth extension examples (#506)
* Drop --url param from web-bot-auth extension examples The --url flag sets the base URL for update.xml and policy templates and defaults to 127.0.0.1. Specifying the customer's domain here breaks extension loading in browser sessions. The intended domain is already covered by --signature-agent, so drop --url from both examples. * Replace Kernel Search configuration section with link to /docs/bots The Kernel Search configuration steps were wrong to expose. Kernel's own Web Bot Auth identities (Kernel Agent, Kernel Search) are already approved by Cloudflare, Vercel, Akamai, etc. Replace the build/env-var instructions with a short note pointing to /docs/bots and telling readers to contact support if they want to sign with Kernel's identities. * Fix /docs/bots -> /bots link in web-bot-auth Mintlify uses the /bots path, not /docs/bots. --------- Co-authored-by: ulziibay-kernel <253135130+ulziibay-kernel@users.noreply.github.com>
1 parent d8b2f66 commit ab38f98

1 file changed

Lines changed: 6 additions & 33 deletions

File tree

‎browsers/bot-detection/web-bot-auth.mdx‎

Lines changed: 6 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -145,44 +145,17 @@ The directory should contain your public keys in JWKS format:
145145
kernel extensions build-web-bot-auth \
146146
--to ./web-bot-auth-ext \
147147
--key ./my-key.jwk \
148-
--url https://yourdomain.com \
149148
--signature-agent https://yourdomain.com \
150149
--upload my-web-bot-auth
151150
```
152151

153-
### 4. Kernel Search configuration
152+
### 4. Using Kernel's bot identities
154153

155-
Kernel Search uses a distinct Web Bot Auth identity from Kernel's user-driven
156-
agent traffic:
157-
158-
- User-Agent: `KernelSearchBot`
159-
- Signature-Agent: `https://search.bot.kernel.sh`
160-
- Key directory:
161-
`https://search.bot.kernel.sh/.well-known/http-message-signatures-directory`
162-
163-
To build a browser extension for Kernel Search, use the Kernel Search Ed25519
164-
private key (JWK) and upload it under a distinct extension name:
165-
166-
```bash
167-
kernel extensions build-web-bot-auth \
168-
--to ./web-bot-auth-search-ext \
169-
--key ./kernel-search.jwk \
170-
--url https://www.kernel.sh \
171-
--signature-agent https://search.bot.kernel.sh \
172-
--upload web-bot-auth-search
173-
```
174-
175-
For host-proxy based signing, configure the Search crawler's host-proxy
176-
environment with:
177-
178-
```bash
179-
HOST_PROXY_WEB_BOT_AUTH_ENABLED=true
180-
HOST_PROXY_WEB_BOT_AUTH_KEY_PATH=/path/to/kernel-search-private-key.pem
181-
HOST_PROXY_WEB_BOT_AUTH_DIRECTORY_URL=https://search.bot.kernel.sh
182-
```
183-
184-
The signing key must correspond to the public key hosted by
185-
`search.bot.kernel.sh`.
154+
Kernel's own Web Bot Auth identities are already approved by Cloudflare, Vercel,
155+
Akamai, and other bot-verification providers. If you want to sign requests with
156+
one of Kernel's identities rather than your own, [contact Kernel support](https://www.kernel.sh/docs/info/support).
157+
See [Bots and agents](/bots) for the list of identities and their key
158+
directories.
186159

187160
### 5. Register with Vercel and other Web Bot Auth-aware directories (optional)
188161

0 commit comments

Comments
 (0)