Skip to content

docs: Clarify opt-in WBA access and improve discovery - #627

Merged
AnnaXWang merged 3 commits into
mainfrom
hypeship/document-wba-access
Sep 25, 2026
Merged

AnnaXWang merged 3 commits into
mainfrom
hypeship/document-wba-access

Conversation

@AnnaXWang

@AnnaXWang AnnaXWang commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

The WBA guide leads with a test-key extension tutorial and doesn't explain who can request the managed WBA token. Add WBA to the title and description, lead with selective opt-in access for Startup and Enterprise plans, and link to the access instructions from the anti-detection overview and stealth guide.

Explain how verifiable identity can reduce challenges and retries on participating sites while preserving site access policies. Keep the test-key and own-key instructions as separate options. Move the complete Bot Anti-Detection navigation group from Advanced to the start of Intermediate without changing page URLs.

Testing

  • mint broken-links passes.
  • mint dev starts; all three edited pages return HTTP 200 with the new content.
  • The rendered request-access heading matches the new cross-links.
  • Navigation JSON is valid and all existing navigation entries are preserved.
  • git diff main...HEAD --check passes; full diff reviewed.

Existing SDK examples are unchanged and were not executed. Search indexing will occur after publication; hosted search wasn't tested locally.

Implementation checklist

No sample app, CLI, or API changes.


Note

Low Risk
Documentation and navigation-only changes with no runtime, API, or SDK behavior impact.

Overview
Documentation updates clarify KERNEL’s Web Bot Auth (WBA) token as a selective, opt-in capability for Startup and Enterprise customers (not default, not automatic with stealth), with a new Request WBA access flow and cross-links from the bot-detection overview and stealth pages.

The WBA guide is reframed to lead with managed-token access and benefits (verifiable identity, fewer challenges on participating sites, site policy limits), while keeping test-key and bring-your-own-keys paths and noting that the public test key does not enable KERNEL’s production identity.

docs.json moves the full Bot Anti-Detection section (including nested Proxies and WBA) from Advanced to the start of Intermediate for easier discovery; page URLs are unchanged.

Reviewed by Cursor Bugbot for commit 69e885e. Bugbot is set up for automated code reviews on this repo. Configure here.

@mintlify

mintlify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
Kernel 🟢 Ready View Preview Sep 25, 2026, 4:24 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Very Low. Approved.

The change is limited to public documentation and sidebar order:

  • browsers/bot-detection/overview.mdx, stealth.mdx, and web-bot-auth.mdx update copy about opt-in Web Bot Auth access and add cross-links. No code samples, APIs, or runtime behavior change.
  • docs.json moves the existing Bot Anti-Detection navigation group from Advanced to the start of Intermediate. The same page paths stay in place; URLs are unchanged. The JSON still parses.

No application logic, auth, permissions, infrastructure, or schema changes. No CODEOWNERS file, so code owner review is not required. No prior approval on this PR.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

[Web Bot Auth (WBA)](https://datatracker.ietf.org/doc/html/draft-meunier-web-bot-auth-architecture) lets your browser agent cryptographically sign requests so participating websites can verify its identity. Sites that recognize and allow that identity can let your agent continue with fewer bot challenges and interruptions.

![Kernel on Vercel's public directory of known bots used across the web](/images/botsfyi.png)
We offer **KERNEL's WBA token** as an **opt-in feature**, enabled selectively on request for **Startup Plan and Enterprise Plan customers**. It's not enabled by default.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Plan details in page intro

Low Severity

The frontmatter description and the paragraph before Request WBA access include plan gating and how to request the managed token. Those details belong in that subsection so the intro stays a high-level orientation on what WBA is.

Fix in Cursor Fix in Web

Triggered by learned rule: Keep page descriptions and intros high-level — push details into subsections

Reviewed by Cursor Bugbot for commit 01a39b5. Configure here.

Comment thread browsers/bot-detection/web-bot-auth.mdx Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Very Low. Re-checked after the branch update. Existing approval stands; not approving again.

The pull request diff against main is still documentation and sidebar order only:

  • browsers/bot-detection/overview.mdx, stealth.mdx, and web-bot-auth.mdx change copy about opt-in Web Bot Auth access and add cross-links. No code samples, APIs, auth logic, or runtime behavior change.
  • docs.json moves the existing Bot Anti-Detection group from Advanced to the start of Intermediate. The same page paths stay in place.

The new commit (9397bfb) only merges main into this branch. Those files are already on main and are not part of this pull request’s unique diff. Risk does not increase, so the prior approval is left in place.

No CODEOWNERS file is present, so code owner review is not required.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

@dprevoznik dprevoznik left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - left one suggestion, but otherwise 🚢 it

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 9397bfb. Configure here.

### [Web Bot Auth (WBA)](/browsers/bot-detection/web-bot-auth)
WBA lets your agent sign requests with a verifiable identity. Participating websites that recognize and allow that identity can reduce bot challenges and interruptions in your workflows.

**KERNEL's WBA token is opt-in**, enabled selectively on request for **Startup Plan and Enterprise Plan customers**. It's not enabled by default. [Request WBA access](/browsers/bot-detection/web-bot-auth#request-wba-access) to use our bot identity. Each site still controls access; WBA doesn't replace login or guarantee that a site will allow your agent.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WBA access policy duplicated

Low Severity

The overview and stealth pages restate WBA opt-in rules, plan eligibility, and access caveats instead of briefly pointing to the canonical Request WBA access section. Those details can drift if the request process changes.

Additional Locations (1)
Fix in Cursor Fix in Web

Triggered by learned rule: Single source of truth — no deep content duplication across pages

Reviewed by Cursor Bugbot for commit 9397bfb. Configure here.

Co-authored-by: Daniel Prevoznik <danny@onkernel.com>
@AnnaXWang
AnnaXWang merged commit c11c32b into main Sep 25, 2026
4 checks passed
@AnnaXWang
AnnaXWang deleted the hypeship/document-wba-access branch September 25, 2026 16:25

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Very Low. Re-checked after the latest commit. Existing approval stands; not approving again.

The new commit (69e885e) changes one word in browsers/bot-detection/web-bot-auth.mdx: “automate” to “access” in the request-access sentence. The rest of the pull request is unchanged and still limited to public documentation and sidebar order:

  • overview.mdx, stealth.mdx, and web-bot-auth.mdx update copy about opt-in Web Bot Auth and add cross-links. No code samples, APIs, auth logic, or runtime behavior change.
  • docs.json moves the existing Bot Anti-Detection group from Advanced to the start of Intermediate. The same page paths stay in place.

Risk does not increase, so the prior approval is left in place. No CODEOWNERS file is present, so code owner review is not required.

Open in Web View Automation 

Sent by Cursor Automation: Assign PR reviewers

This branch was successfully deployed

1 active deployment
staging — 69e885e8 Deployed Sep 25, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants