AI agents are getting better at doing things on the internet. That creates a surprisingly ordinary problem: businesses need to know who — or what — is knocking on the door.
For years, websites mostly divided traffic into humans and bots. Humans logged in. Software used API keys. Bots were tolerated, rate-limited or blocked. Agents blur those categories because they can browse, call tools, act for a person and move between systems. “It came from a computer” is no longer much of an identity.
Three separate systems are pointing in the same direction
Shopify now tells bots and agents that access storefronts to sign requests with Web Bot Auth if they want higher rate limits. Okta’s Agent SSO lets an enterprise register an AI agent as a workload principal and connect it to applications under administrator-controlled policies. Cloudflare is building related identity controls around signed agent traffic and Web Bot Auth.
Those are different products solving different problems, which is exactly why the convergence matters. Shopify cares about storefront traffic. Okta cares about enterprise access. Cloudflare sits in front of websites and AI infrastructure. All three are arriving at a similar conclusion: an agent needs an identity that systems can recognize and govern.
An agent that can act like an employee eventually needs controls that look a lot more like employee controls.
Why borrowed human credentials are a bad long-term answer
The easy shortcut is to let an agent operate with a person’s credentials. That works right up until somebody asks basic questions: Which agent performed the action? Who owns it? What was it allowed to do? Can we revoke only the agent without disabling the person? Can we tell automated activity from human activity in an audit?
Those questions sound like IT administration because they are. The interesting part is that they are becoming ecommerce and website questions too. An agent may search products, check inventory, negotiate access to an API, initiate a purchase or interact with customer data. Identity becomes the layer that lets a business say, “this machine is known, it belongs to this owner, and these are its limits.”
Commerce makes the problem harder
Discovery is relatively forgiving. Buying is not. The moment an agent can spend money, request a return, change an order or access an account, identity connects directly to authorization and accountability.
Cloudflare has described a related obstacle for agentic commerce: agents need stable ways to identify themselves and, increasingly, transact. That does not mean every shopping bot needs a corporate badge tomorrow. It does mean the current internet was mostly designed around humans proving who they are and software authenticating through narrowly defined integrations. Agents sit awkwardly between those models.
The more authority we hand to agents, the less acceptable anonymous automation becomes.
What businesses should actually do
Most businesses do not need an “AI agent identity strategy” meeting this week. That sentence alone sounds expensive. But they should start asking better questions whenever an agent is given real access: Does it have its own credential? Is there a named owner? Can its permissions be limited? Can its activity be audited? Can access be revoked without breaking the human account behind it?
For ecommerce operators, also watch how major platforms begin distinguishing authenticated agents from ordinary bots. Shopify’s rate-limit treatment is an early example of a practical incentive: identify yourself and the platform can treat you differently.
The caveat
This is still emerging infrastructure, not a finished universal standard. Web Bot Auth and Cross App Access are not yet a common identity layer for the whole internet, and broad merchant adoption is not established. It would be premature to declare that every AI agent will soon carry one portable credential everywhere.
But the direction is becoming harder to dismiss. When website infrastructure, commerce platforms and enterprise identity vendors independently start building ways to identify and govern agents, the problem has moved beyond a theoretical security discussion.
The web spent decades getting reasonably good at asking humans to prove who they are. Now it has a new visitor. Unsurprisingly, the first question is becoming the same one: who are you, and what exactly are you allowed to do here?
Sources
Ready to scale your brand?
Let's talk about what growth looks like for your business.
Book a Free Strategy Call