AgentIsOK is looking for one origin-side design partner to test a narrow question: can request-bound agent clearance help an origin admit desirable automated traffic without weakening abuse controls or centralizing trust?
The first pilot is deliberately non-enforcing. Your existing WAF, CAPTCHA, bot product, or application policy remains authoritative, and the origin controls the verifier and metrics.
A strong first workflow:
- receives legitimate automated requests that current controls sometimes challenge or block;
- is low consequence, such as bounded availability or inventory search;
- has a security, fraud, identity, bot-management, or platform owner;
- offers some usable outcome signal; and
- can expose a safe shadow integration point with a kill switch.
AgentIsOK supplies the open draft, schemas, 17 conformance vectors, reference loop, a Fetch-standard edge adapter, and a privacy-minimized metrics contract. No AgentIsOK account, hosted verifier, central directory, or production authorization is required.
Start with the pilot packet and origin interview guide. If the fit seems plausible, comment with only a high-level workflow and the role you play. Do not post confidential traffic, customer data, credentials, or security details here.
Direct APIs, ordinary OAuth, or Web Bot Auth alone may be the better answer for some workflows. Discovering that early is a useful result, not a failed pitch.
AgentIsOK is looking for one origin-side design partner to test a narrow question: can request-bound agent clearance help an origin admit desirable automated traffic without weakening abuse controls or centralizing trust?
The first pilot is deliberately non-enforcing. Your existing WAF, CAPTCHA, bot product, or application policy remains authoritative, and the origin controls the verifier and metrics.
A strong first workflow:
AgentIsOK supplies the open draft, schemas, 17 conformance vectors, reference loop, a Fetch-standard edge adapter, and a privacy-minimized metrics contract. No AgentIsOK account, hosted verifier, central directory, or production authorization is required.
Start with the pilot packet and origin interview guide. If the fit seems plausible, comment with only a high-level workflow and the role you play. Do not post confidential traffic, customer data, credentials, or security details here.
Direct APIs, ordinary OAuth, or Web Bot Auth alone may be the better answer for some workflows. Discovering that early is a useful result, not a failed pitch.