Back to browse
Tool to validate your HTTP-message-signatures-directory

Tool to validate your HTTP-message-signatures-directory

by zeppelin_7·Jul 24, 2026·3 points·0 comments

AI Analysis

●●SolidNiche GemSolve My Problem

Catches leaked private keys before Cloudflare rejects your crawler.

Strengths
  • Validates against the specific RFC 9421 standard for HTTP Message Signatures.
  • Checks for critical security failures like accidentally published private keys.
  • Zero-data retention policy ensures sensitive key material isn't logged.
Weaknesses
  • Extremely narrow audience limited to those implementing the new Web Bot Auth spec.
  • Functionality is a single-purpose validator that could easily be a CLI script.
Target Audience

Crawler operators and infrastructure engineers implementing Web Bot Auth

Similar To

Cloudflare Bot Management · letsencrypt-checker

Post Description

I run a crawler (SitedexBot) that signs every request using Web Bot Auth. I was trying to debug my HTTP message signatures directory, and ended up making the tool free/open.

No data is stored after the keycheck. You can validate your http-message-signatures-directory and ensure you are web bot auth compliant.

Similar Projects

Security●●Solid

Seamless Auth – open-source passwordless authentication

Implements real WebAuthn/passkey support plus OTP and HTTP-only cookie session validation, and exposes JWKS and token endpoints — plus an npx create-seamless scaffold and Docker Compose so you can stand up the stack in minutes. The repo deliberately focuses on the auth engine (no admin UI or hosted control plane), which makes it easy to audit and integrate; still, the space is crowded with Ory/Keycloak/Supabase, so this is best if you specifically want a lean, self-hostable passwordless core.

Niche GemShip It
bccorb1000
305mo ago