The Agent Architect · 2026-W40
The Agent Architect #40: Web Bot Auth (Signed Agents)
Preview: this issue goes out Tuesday 08:00 UTC.
Listen to the latest issue · 6 min
Pattern of the week
Web Bot Auth (Signed Agents)
- What:
- Agent cryptographically signs each HTTP request with Ed25519, publishes public keys at /.well-known/http-message-signatures-directory, and origin verifies signature to allow, deny, rate-limit, or price traffic.
- When to use it:
- Origins need to distinguish legitimate agents from scrapers and grant different access tiers based on verified agent identity rather than spoofable IP ranges or User-Agent headers.
- Watch out:
- Key rotation and expiry window management become operational burdens; misconfigured signature validation opens doors to replay attacks or signature forgery if not implemented precisely.
This week in agentic AI
- Announcing vllm-metal: Concurrent Serving on Apple SiliconvLLM
vllm-metal brings vLLM's serving stack to Apple Silicon with lower time-to-first-token under concurrent load.
- Gemini 3.8 text-to-speech says helloGoogle DeepMind
Gemini 3.8 text-to-speech model released.
- Better prompt caching for GPT-6OpenAI
GPT-6 improves prompt caching with higher hit rates, diagnostics, explicit breakpoints, and controls to reduce latency and costs.
- DeepEdu-v1: Efficient and Scalable Agentic LLMs for Vietnamese EducationarXiv cs.AI
DeepEdu-v1 provides efficient Vietnamese language tutoring using local LLMs aligned with national curriculum.
- Introducing LangSmith Fine-TuningLangChain
LangChain released LangSmith Fine-Tuning and SmithTune CLI for model post-training without manual data pipelines.
The Agent Architect
One pattern, one tradeoff, one production failure story. A short weekly briefing for people building agentic systems.
Weekly email, one-click unsubscribe. We only use your address to send the briefing.