For website owners

Vardia agent

Vardia is a personal assistant people message on Telegram. When someone asks it to buy cinema tickets, order groceries, book a home service or cancel a subscription, its agent opens your site in a browser and does what that person would do. This page explains how it behaves, how to verify it, and how to allow or block it.

Last updated 26 September 2026

At a glance

NameVardia agent
OperatorVardia · vardia.co
What it isA browsing agent that acts for one person at a time, only when they ask
Access typeUser-initiated (Cloudflare: Intermediary)
IdentificationWeb Bot Auth: HTTP Message Signatures (RFC 9421), Ed25519
Signature-Agent"https://app.vardia.co"
Key directoryhttps://app.vardia.co/.well-known/http-message-signatures-directory
Key IDMx7KYBTgVbcx0E4rjmoCjckHen-7ExIdevvVkCeXzNk
User agentA standard Chrome user agent. Identify us by the signature, not the user agent
IP addressesNot fixed. Verify the signature instead of allowlisting IPs
robots.txt tokenVardiaAgent
Contact[email protected]

How it behaves

Every visit starts with a request from a Vardia user, for one specific task on your site.

It never:

Verifying requests

Vardia signs every request with Web Bot Auth (HTTP Message Signatures, RFC 9421, Ed25519). Each request carries three headers:

Example

Signature-Agent: "https://app.vardia.co"
Signature-Input: sig1=("@authority" "signature-agent");created=1790638648;keyid="Mx7KYBTgVbcx0E4rjmoCjckHen-7ExIdevvVkCeXzNk";alg="ed25519";expires=1790638708;nonce="r07rYX3KuoySn7OF+rq+tGm0GdlBK0JOx1w9ls079KDpU8F5ZZe2fVXlCHyX6qi/";tag="web-bot-auth"
Signature: sig1=:14zcShAdfboqCX+aOaAfKhtrbaIr2DhuhE4hgxCezxO0QHn+QablF85AUZ3vuryeoQy3fX+/OAep3l/TJsIDDQ==:

Cloudflare, Akamai, AWS WAF, HUMAN, Vercel and DataDome can verify Web Bot Auth signatures automatically. To verify them yourself:

  1. Check that Signature-Agent is exactly "https://app.vardia.co".
  2. Fetch our public keys from https://app.vardia.co/.well-known/http-message-signatures-directory. That response is itself signed (tag="http-message-signatures-directory").
  3. Verify Signature and Signature-Input per RFC 9421 with the key whose JWK thumbprint matches keyid, and check created and expires.
  4. Treat the request as Vardia only if the signature verifies.

Allowing Vardia

If your bot protection challenges or blocks Vardia and you're happy for your customers to use it, allow requests whose Web Bot Auth signature verifies with Signature-Agent: "https://app.vardia.co". In services that verify signatures for you, allow the verified agent Vardia agent once it appears in their directory. We never ask you to lower your protection in general: only verified Vardia requests.

Blocking or limiting Vardia

You're in control. Any of these works:

When a site opts out, Vardia tells the person it can't help on that site and suggests alternatives.

robots.txt

Because every visit is requested by a person, like a visit from their own browser, general crawling rules for all bots (User-agent: *) aren't applied. Rules for our token always are:

# Keep Vardia's agent out of the whole site
User-agent: VardiaAgent
Disallow: /

# Or only out of some paths
User-agent: VardiaAgent
Disallow: /account/
Allow: /account/login

The agent reads your robots.txt before it opens your site and again at most an hour later (changes take effect within an hour). Allow, Disallow, * and a final $ work as in major crawlers; the longest matching rule wins.

Data

Troubleshooting

Contact

Questions, problems with our traffic, or opt-out requests: [email protected]. We reply within two working days.