<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web Bot Auth on Eknix — Web security &amp; performance for the enterprise</title><link>https://www.eknix.com/tags/web-bot-auth/</link><description>Recent content in Web Bot Auth on Eknix — Web security &amp; performance for the enterprise</description><generator>Hugo</generator><language>en-us</language><copyright>© {year} EKNIX LTD. All rights reserved.</copyright><lastBuildDate>Wed, 22 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.eknix.com/tags/web-bot-auth/index.xml" rel="self" type="application/rss+xml"/><item><title>One in Forty 'Trusted' Bots Is an Impostor. Your Allow-List Lets It Right In.</title><link>https://www.eknix.com/blog/ai-agent-verification/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://www.eknix.com/blog/ai-agent-verification/</guid><description>&lt;p&gt;Roughly one in every forty requests claiming to be PerplexityBot is a fake.&lt;/p&gt;
&lt;p&gt;Not a rounding error. Not a theoretical risk. DataDome measured it across 7.9 billion AI agent requests in January and February of this year: nearly 2.4% of everything wearing Perplexity&amp;rsquo;s name was an impostor. Meta&amp;rsquo;s agent had it worse, with 16.4 million spoofed requests in those same two months.&lt;/p&gt;
&lt;p&gt;Now the uncomfortable part. If your bot policy has an allow-list, and almost every bot policy does, those impostors are not sneaking past your defenses. Your defenses are holding the door for them, because the allow-list checks names, and a name is text anyone can type.&lt;/p&gt;</description></item></channel></rss>