Next.js
Authenticate every agent in a Next.js App Router app — middleware for all requests, the provider for in-page agents.
Next.js
Two pieces: middleware authenticates every request (signed agents, API agents, crawlers), and the provider authenticates agents operating your pages. Start with the middleware.
1. Install
2. Middleware
Every request continues to your app — verified agents with their identity attached, everything else exactly as before. Agentronics never blocks.
Edge or Node.js runtime?
Everything except verified crawlers works on the edge
runtime. Reverse DNS needs Node, so set runtime: 'nodejs' (Next.js 15.5+). On the edge,
crawler claims stay unverified — never wrongly verified.
Already using Clerk (or another auth middleware)?
Compose them — run agent auth first, then your user auth:
3. Use the verified agent
In route handlers and server components:
These headers are only trustworthy on routes behind the middleware — it strips any forged
x-agentronics-* header before setting them.
4. In-page agents (optional)
To authenticate WebMCP clients and browser agents operating your pages, mount the provider:
Wrap your root layout with it, then use useAgentronics() to reach the client
(client.detect(), client.authenticate()). See
WebMCP & browser agents.
5. Send auth logs to the console
onResult never delays or affects the request. See Stream auth events to the console.