Cloudflare has announced a collaborative technology initiative alongside major web browser developers of Mozilla Firefox, Google Chrome, Microsoft Edge, etc, to design and standardize a new privacy-preserving authentication framework called Private Access Control Tokens (PACT).

Cloudflare for AI

The proposed protocol aims to establish an open standard that allows legitimate internet traffic to verify its authenticity across web servers, addressing the growing volume of automated traffic driven by consumer-grade AI agents. The core cryptographic architecture is designed to minimize user friction by allowing digital platforms with pre-existing validation of a user’s “personhood” to issue anonymous, unlinkable security tokens.

A user’s local web browser can then present these tokens to secondary internet sites to prove that a real human or authorized automated agent is directing the traffic session, reducing the necessity for intrusive tracking scripts, forced user accounts, or repetitive graphical CAPTCHA puzzles.

From the technical side of things, this enforces strict user data boundaries by keeping individual tokens entirely anonymous and cryptographically distinct. Under this setup, the original token issuer cannot track where the credential is spent, the receiving web server cannot map the token back to a persistent user identity, and separate token presentations cannot be cross-referenced to compile an individual’s cross-site browsing history.

The open-standard development has also garnered operational support from e-commerce platform Shopify, which intends to implement the verified token mechanism to help its network of merchant sites distinguish authentic consumer activity and authorized purchasing agents from distributed, malicious automated scraping bots without introducing transaction friction.

Cloudflare has committed to developing the core protocol parameters and submitting the completed framework to international web standards bodies for formal review, with the rollout following a broader structural shift across web security landscapes as traditional boundary checks, text-matching filters, and binary block-or-allow firewalls struggle to parse non-deterministic traffic patterns generated by independent software agents executing routine consumer tasks on behalf of users.

Facebook
Twitter
LinkedIn
Pinterest

Related Posts

Subscribe via Email

Enter your email address to subscribe to Tech-Critter and receive notifications of new posts by email.