Vardia agent
Vardia is a personal assistant people message on Telegram. When someone asks it to buy cinema tickets, order groceries, book a home service or cancel a subscription, its agent opens your site in a browser and does what that person would do. This page explains how it behaves, how to verify it, and how to allow or block it.
Last updated 26 September 2026
At a glance
| Name | Vardia agent |
|---|---|
| Operator | Vardia · vardia.co |
| What it is | A browsing agent that acts for one person at a time, only when they ask |
| Access type | User-initiated (Cloudflare: Intermediary) |
| Identification | Web Bot Auth: HTTP Message Signatures (RFC 9421), Ed25519 |
| Signature-Agent | "https://app.vardia.co" |
| Key directory | https://app.vardia.co/.well-known/http-message-signatures-directory |
| Key ID | Mx7KYBTgVbcx0E4rjmoCjckHen-7ExIdevvVkCeXzNk |
| User agent | A standard Chrome user agent. Identify us by the signature, not the user agent |
| IP addresses | Not fixed. Verify the signature instead of allowlisting IPs |
| robots.txt token | VardiaAgent |
| Contact | [email protected] |
How it behaves
Every visit starts with a request from a Vardia user, for one specific task on your site.
- One browser session per request, at human pace. It visits the pages that task needs (usually a few to a few dozen) and nothing else.
- Each task runs in a fresh private browser that is deleted when the task ends.
- Every request is signed, so you can tell Vardia apart from anonymous automation.
- It uses guest checkout where you offer it, rejects optional cookies, and unticks newsletters and marketing.
- Nothing is bought or cancelled without the person's explicit approval (for purchases, of the exact items and total), and the person pays you directly with a method you offer.
It never:
- crawls, scrapes or indexes your site, or visits pages no user asked about;
- uses your content to train AI models;
- creates an account without the person's explicit consent (and never one that needs a password: then the person signs up themselves), or types passwords: it signs in only to the person's own account, with their phone or email and a one-time code they give it; a password the person types themselves;
- submits anything to a public authority: on official portals it only fills in forms, and the person presses the final submit;
- solves CAPTCHAs or tries to get around bot protection: when you show a challenge, the person handles it or the task stops;
- enters card numbers or security codes. It pays with a method already saved in the person's own account only after they approve that exact total and method.
Verifying requests
Vardia signs every request with Web Bot Auth (HTTP Message Signatures, RFC 9421, Ed25519). Each request carries three headers:
Signature-Agent, always exactly"https://app.vardia.co", including the quotation marks;Signature-Input, covering@authorityandsignature-agent, withtag="web-bot-auth",alg="ed25519", our key ID and a validity of 60 seconds;Signature, the Ed25519 signature.
Example
Signature-Agent: "https://app.vardia.co"
Signature-Input: sig1=("@authority" "signature-agent");created=1790638648;keyid="Mx7KYBTgVbcx0E4rjmoCjckHen-7ExIdevvVkCeXzNk";alg="ed25519";expires=1790638708;nonce="r07rYX3KuoySn7OF+rq+tGm0GdlBK0JOx1w9ls079KDpU8F5ZZe2fVXlCHyX6qi/";tag="web-bot-auth"
Signature: sig1=:14zcShAdfboqCX+aOaAfKhtrbaIr2DhuhE4hgxCezxO0QHn+QablF85AUZ3vuryeoQy3fX+/OAep3l/TJsIDDQ==:
Cloudflare, Akamai, AWS WAF, HUMAN, Vercel and DataDome can verify Web Bot Auth signatures automatically. To verify them yourself:
- Check that
Signature-Agentis exactly"https://app.vardia.co". - Fetch our public keys from
https://app.vardia.co/.well-known/http-message-signatures-directory. That response is itself signed (tag="http-message-signatures-directory"). - Verify
SignatureandSignature-Inputper RFC 9421 with the key whose JWK thumbprint matcheskeyid, and checkcreatedandexpires. - Treat the request as Vardia only if the signature verifies.
Allowing Vardia
If your bot protection challenges or blocks Vardia and you're happy for your customers to use it, allow requests whose Web Bot Auth signature verifies with Signature-Agent: "https://app.vardia.co". In services that verify signatures for you, allow the verified agent Vardia agent once it appears in their directory. We never ask you to lower your protection in general: only verified Vardia requests.
Blocking or limiting Vardia
You're in control. Any of these works:
- Add a
VardiaAgentrule to your robots.txt (below). The agent checks it before visiting and respects it. - Block or challenge requests with
Signature-Agent: "https://app.vardia.co", or the verified agent Vardia agent, in your firewall or bot management. - Email [email protected] and we'll stop visiting your site.
When a site opts out, Vardia tells the person it can't help on that site and suggests alternatives.
robots.txt
Because every visit is requested by a person, like a visit from their own browser, general crawling rules for all bots (User-agent: *) aren't applied. Rules for our token always are:
# Keep Vardia's agent out of the whole site
User-agent: VardiaAgent
Disallow: /
# Or only out of some paths
User-agent: VardiaAgent
Disallow: /account/
Allow: /account/login
The agent reads your robots.txt before it opens your site and again at most an hour later (changes take effect within an hour). Allow, Disallow, * and a final $ work as in major crawlers; the longest matching rule wins.
Data
- Vardia uses the pages it visits only to complete that person's task. It doesn't build an index of your content or use it to train models.
- For support, it keeps screenshots and a log of the steps of each task for 30 days, then deletes them.
- The person's details (name, email, delivery address) are entered on your site only for an order they approved.
- Logins happen only in the task's private browser, which is deleted when the task ends. Vardia never stores passwords or login sessions.
Troubleshooting
- Signatures don't verify: make sure proxies, load balancers and CDNs in front of your site keep the
Signature,Signature-InputandSignature-Agentheaders unchanged. - Expired signatures: each signature is valid for 60 seconds. Check your servers' clocks are in sync.
- Something looks wrong: write to us with the time, the URL and, if you have them, the request headers. We'll look into it.
Contact
Questions, problems with our traffic, or opt-out requests: [email protected]. We reply within two working days.