For site owners

CatPaw on your site

If a User-Agent on your site contains CatPaw, a browser driven by an AI agent visited it, for a person who gave the agent a task. This page says what that traffic is, how to recognise it, and how to block or allow it.

What it is

A browser, not a crawler

CatPaw is an open-source browser that AI agents use on behalf of the people they work for. It does not follow links by itself. It loads the pages an agent asks for, with the style sheets, scripts and frames those pages need, and it runs the pages' JavaScript as a browser does.

Under its default policy, a form submission or a file upload waits until the person approves it. Whoever runs CatPaw can change that policy.

CatPaw is software that people install and run themselves. The requests you see come from whoever runs it. The CatPaw project does not sign requests and holds no keys for anyone.

Recognising it

It says what it is

From version 0.1, CatPaw sends this User-Agent, and reports the same value to pages as navigator.userAgent:

CatPaw/<version> (+https://catpaw.sh/bot)

For example CatPaw/0.1.0 (+https://catpaw.sh/bot). Scripts on your pages also see navigator.webdriver as true, as the WebDriver standard asks of a browser under automation; CatPaw always reports it.

Whoever runs CatPaw can change the User-Agent header, as with any HTTP client, so treat it as a statement rather than proof. A signature, described below, is proof of who sent a request.

What it does not do

No disguise, no CAPTCHA solving

  • It does not pretend to be another browser. It ships no profiles that imitate other browsers' fingerprints, and it does not tune TLS or HTTP/2 settings to match them.
  • It does not solve CAPTCHAs and has no integration with solving services. When a page shows a check meant for people, the agent can hand the tab to its user. The person sees the page in their own browser and answers the check themselves; the page stays in CatPaw, and their clicks and keys are passed to it.
  • It has no residential-proxy rotation. The project does not accept CAPTCHA solving, fingerprint impersonation or proxy rotation as features (ADR 0003).
  • It does not read robots.txt. To keep CatPaw off your site, block it by User-Agent as shown below.

CatPaw will not pass every site, and that is the site owner's decision.

Blocking or allowing

Match the CatPaw token

Match CatPaw in the User-Agent header. Some examples:

nginx, inside a server or location block
if ($http_user_agent ~* "CatPaw") {
    return 403;
}
Apache, with mod_rewrite
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} CatPaw [NC]
RewriteRule ^ - [F]
Cloudflare, a custom rule expression with the Block action
(http.user_agent contains "CatPaw")

To allow one deployment you trust rather than all CatPaw traffic, check its signature rather than the User-Agent.

Signed requests

Web Bot Auth

Whoever runs CatPaw can sign its requests with Web Bot Auth: HTTP Message Signatures (RFC 9421) with the web-bot-auth tag, using an Ed25519 key of their own. They make the key with catpaw keygen and pass it with --bot-auth-key and --signature-agent. A signed request carries three headers:

Signature-Agent: sig="https://agent.example"
Signature-Input: sig=("@method" "@authority" "@path" "signature-agent";key="sig");created=...;expires=...;keyid=...;nonce=...;alg="ed25519";tag="web-bot-auth"
Signature: sig=:...:

The public key is published at <Signature-Agent origin>/.well-known/http-message-signatures-directory, and keyid is its JWK thumbprint (RFC 7638). A valid signature tells you which deployment sent the request. It does not mean the CatPaw project vouches for that deployment: the project does not sign requests or register with anyone. Deployers who want a verified identity register as Signed Agents with Cloudflare themselves, and Cloudflare shows the result to site owners in its rules.

Contact

Who to tell

  • About traffic from a particular deployment: its operator. If the requests are signed, the Signature-Agent header names them.
  • About CatPaw itself, such as a bug or a question: GitHub issues.
  • Security reports: a private security advisory on GitHub.