Frameworks
Express
Authenticate agents in an Express (or Connect) app with one middleware.
Express
The middleware:
- sets
req.agentto the result (verified,unverifiedornone), - sets the
x-agentronics-*request headers for downstream code (forged ones are removed first), - always calls
next()— every request reaches your routes. If authentication fails internally,req.agentis{ status: 'none' }and the request carries on.
For TypeScript, extend the request type:
Client IP behind a proxy
Verified crawlers need the real client IP. By default only
cf-connecting-ip, x-real-ip and x-vercel-forwarded-for are read. If your load balancer
sets something else, pass crawlers.clientIp as above. Never trust the leftmost
X-Forwarded-For entry — the caller controls it.