Skip to content

invalid_signature

HTTP 401 · Ludion-Error: invalid_signature

Your request carried a Web Bot Auth signature, the Gate found your key, and the signature did not hold. The Gate treats that as a spoofing attempt, whatever the cause. Common causes:

  • the request changed after signing (a proxy rewrote a header, the body changed);
  • the signature was made for another host: @authority must be this site;
  • the clock: created is in the future, or expires has passed, beyond ±30 seconds of skew (spec §10.4);
  • the lifetime expires − created is longer than 60 seconds (spec §10.4);
  • tag is not web-bot-auth, or the Signature-Agent dictionary key does not match the signature label;
  • the same signature (or nonce) was sent again: a signature cannot be reused.

A signature is only worth something if a forged or replayed one never passes. The Gate rejects every signature it cannot verify exactly as sent, so that no one can borrow your name, and so that you can trust a VERIFIED result about anyone else.

  • Make a new signature for every request, just before sending it, and change nothing afterwards.
  • Sign for the host you are calling, and keep the lifetime at 60 seconds or less (spec §10.4).
  • Sync your clock (NTP). npx ludion doctor shows the time it signs with.
  • For POST, PUT, PATCH and DELETE, also cover @method, @path and content-digest. npx ludion sign does this for you.

Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.

Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.

  1. Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.

    Terminal window
    npx ludion init --name "My Agent" --contact mailto:you@example.com
  2. Publish the public files it wrote at your Signature-Agent origin over HTTPS: .well-known/http-message-signatures-directory (your keys, served as application/http-message-signatures-directory+json) and card (who you are). Your own domain works; so will dvr-….agents.ludion.ai once registration opens.

  3. Sign each request. This prints a ready-to-run curl with the Signature-Agent, Signature-Input and Signature headers; a signature lives 60 seconds (spec §10.4), so make a new one per request.

    Terminal window
    npx ludion sign GET https://shop.example/checkout --curl
  4. Check yourself. doctor fetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.

    Terminal window
    npx ludion doctor

A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.