Authentication for AI agents.
Verify every agent on your site — signed agents, API agents, crawlers, WebMCP and browser agents — with any method. No blocking: agents that don't authenticate browse as normal.
// middleware.ts
import { agentronicsMiddleware } from '@agentronics/sdk/next'
export default agentronicsMiddleware()
// every request continues; verified agents carry x-agentronics-* headersWeb Bot Auth
Verify cryptographically signed agents — RFC 9421 HTTP message signatures, as used by OpenAI’s ChatGPT agent.
→Agent API keys
Issue keys to the agents you and your customers run; verified on every request, hashed at rest.
→Verified crawlers
Tell real Googlebot, Bingbot and Applebot from scrapers wearing their user agent.
→OAuth2 & enterprise identity
Client-credentials tokens, SSO/OIDC, SPIFFE and mTLS for agents with an identity provider.
→Identity in your app
Verified agents reach your routes with who they are attached. Nothing is ever blocked — unverified agents browse as normal.
→Auth logs & sessions
Every sign-in, the method, and why it passed or failed — streamed to the console.
→