Other

GET/api/web-bot-auth/directory

Get the Web Bot Auth signature agent card (public keys for verifying ora's crawler)

Returns ora's Web Bot Auth signature agent card: the client name, contact, stated purpose, and the public Ed25519 keys that verify HTTP Message Signatures (RFC 9421) on requests from ora's scanner. Bot-management verifiers resolve a signed request's `keyid` against the `kid` of a key here. Also served at /.well-known/http-message-signatures-directory via a rewrite, which is the path the specification fixes and the one verifiers fetch. `keys` is an empty array when no signing key is configured, so the endpoint is always valid JSON and can be probed unconditionally.

RESPONSES
200The signature agent card ({ client_name, homepage_uri, contact_email, purpose, keys: [...] }).