---
title: "AI agents can sign themselves up, and every request we send is signed"
description: "An AI agent can now register for a Linkbreakers workspace on its own and hand it to you with a 6-digit code. Webhooks and link checks now carry Web Bot Auth signatures you can verify."
canonical: "https://linkbreakers.com/help/article/agents-register-themselves-and-signed-requests"
last-updated: 2026-10-10
---

# AI agents can sign themselves up, and every request we send is signed

> An AI agent can now register for a Linkbreakers workspace on its own and hand it to you with a 6-digit code. Webhooks and link checks now carry Web Bot Auth signatures you can verify.

## Short answer

An AI agent no longer needs you to create an account or an API token before it can work. It registers itself, gets a workspace on the free plan and a token, and builds your links and QR codes. When you want the workspace, the agent gives you a link and a 6-digit code, and you claim it in one step. Separately, every webhook and every link check Linkbreakers sends now carries a cryptographic signature, so you can prove a request came from us.

## What we shipped

### Agent self-registration

We implemented the anonymous flow of the [auth.md](/auth.md) agent registration profile. An agent calls our authorization server and receives:

- a workspace of its own, on the free plan with its usual limits
- an API token limited to links, QR codes, workflows, page themes and analytics
- a claim token it can turn into a link and a code for you

You open the link, enter the code, and save a password or sign in with Google or Microsoft. The workspace and everything the agent built become yours. The agent keeps working in it, and you can cut it off at any time by deleting its token under Workspace, API tokens. A workspace nobody claims is removed after 24 hours.

### Signed webhooks and link checks

Webhooks and the requests we make to check link destinations now carry [HTTP Message Signatures](https://www.rfc-editor.org/rfc/rfc9421) following Web Bot Auth. Our public keys are at `https://linkbreakers.com/.well-known/http-message-signatures-directory`. Webhook signatures also cover a digest of the body, so you can check the payload was not changed. See [Verify Linkbreakers webhook signatures](/help/article/verify-webhook-signatures) for code in Node.js and Python.

## Frequently asked questions

### Can an agent create unlimited accounts?

No. Registrations are rate limited per address and overall, each workspace is on the free plan with its limits, every link still goes through our malware checks, and unclaimed workspaces are deleted after a day.

### What can the agent do after I claim the workspace?

It can also upload media, manage webhooks and dashboards, and update visitors. It never gets custom domains, integrations, members, API tokens, billing or workspace settings. The claim page lists exactly what it is allowed.

### Do I need to change anything for signed webhooks?

No. Existing webhooks keep working. Verifying the signature is optional and recommended.
