Skip to content

Commit caac065

Browse files
Replace Kernel Search configuration section with link to /docs/bots
The Kernel Search configuration steps were wrong to expose. Kernel's own Web Bot Auth identities (Kernel Agent, Kernel Search) are already approved by Cloudflare, Vercel, Akamai, etc. Replace the build/env-var instructions with a short note pointing to /docs/bots and telling readers to contact support if they want to sign with Kernel's identities.
1 parent 5833c1f commit caac065

1 file changed

Lines changed: 6 additions & 31 deletions

File tree

‎browsers/bot-detection/web-bot-auth.mdx‎

Lines changed: 6 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -149,38 +149,13 @@ kernel extensions build-web-bot-auth \
149149
--upload my-web-bot-auth
150150
```
151151

152-
### 4. Kernel Search configuration
152+
### 4. Using Kernel's bot identities
153153

154-
Kernel Search uses a distinct Web Bot Auth identity from Kernel's user-driven
155-
agent traffic:
156-
157-
- User-Agent: `KernelSearchBot`
158-
- Signature-Agent: `https://search.bot.kernel.sh`
159-
- Key directory:
160-
`https://search.bot.kernel.sh/.well-known/http-message-signatures-directory`
161-
162-
To build a browser extension for Kernel Search, use the Kernel Search Ed25519
163-
private key (JWK) and upload it under a distinct extension name:
164-
165-
```bash
166-
kernel extensions build-web-bot-auth \
167-
--to ./web-bot-auth-search-ext \
168-
--key ./kernel-search.jwk \
169-
--signature-agent https://search.bot.kernel.sh \
170-
--upload web-bot-auth-search
171-
```
172-
173-
For host-proxy based signing, configure the Search crawler's host-proxy
174-
environment with:
175-
176-
```bash
177-
HOST_PROXY_WEB_BOT_AUTH_ENABLED=true
178-
HOST_PROXY_WEB_BOT_AUTH_KEY_PATH=/path/to/kernel-search-private-key.pem
179-
HOST_PROXY_WEB_BOT_AUTH_DIRECTORY_URL=https://search.bot.kernel.sh
180-
```
181-
182-
The signing key must correspond to the public key hosted by
183-
`search.bot.kernel.sh`.
154+
Kernel's own Web Bot Auth identities are already approved by Cloudflare, Vercel,
155+
Akamai, and other bot-verification providers. If you want to sign requests with
156+
one of Kernel's identities rather than your own, [contact Kernel support](https://www.kernel.sh/docs/info/support).
157+
See [Bots and agents](/docs/bots) for the list of identities and their key
158+
directories.
184159

185160
### 5. Register with Vercel and other Web Bot Auth-aware directories (optional)
186161

0 commit comments

Comments
 (0)