signature_required
HTTP 401 · Ludion-Error: signature_required
What happened
Section titled “What happened”Your request reached a route where the site asks automated clients to sign, and the site’s Ludion Gate could not tie it to a verifiable agent. Either it carried no Web Bot Auth signature, or it carried one whose key the Gate could not find: the key directory named in Signature-Agent was unreachable, or it did not list the signing key. The response includes an Accept-Signature header describing what to sign.
People using a browser are never sent here. The Gate only asks this of clients that look automated, and only on the routes the site chose.
Why this site asks
Section titled “Why this site asks”The site has raised its Pressure on this route, usually a checkout, a login or a form. Unsigned automation there is how scraping, stock hoarding and account takeover happen, and the site cannot tell a careful agent from a careless one without a signature. It is not blocking agents. It is asking which one you are.
How to fix it
Section titled “How to fix it”- Sign the request with Web Bot Auth, covering at least
@authorityandsignature-agent. TheAccept-Signatureheader in this response lists the components the site expects. - If you already sign, run
npx ludion doctoror fetch your directory yourself. It must answer200without redirects, withContent-Type: application/http-message-signatures-directory+json, and list thekeyidyou signed with. - Rarely, this code means the site’s Gate itself could not finish verifying (a fault on its side, with the route set to fail closed). If your setup checks out, retry later.
Get verified in 3 minutes
Section titled “Get verified in 3 minutes”Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.
Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.
-
Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.
Terminal window npx ludion init --name "My Agent" --contact mailto:you@example.com -
Publish the public files it wrote at your
Signature-Agentorigin over HTTPS:.well-known/http-message-signatures-directory(your keys, served asapplication/http-message-signatures-directory+json) andcard(who you are). Your own domain works; so willdvr-….agents.ludion.aionce registration opens. -
Sign each request. This prints a ready-to-run
curlwith theSignature-Agent,Signature-InputandSignatureheaders; a signature lives 60 seconds (spec §10.4), so make a new one per request.Terminal window npx ludion sign GET https://shop.example/checkout --curl -
Check yourself.
doctorfetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.Terminal window npx ludion doctor
A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.