docs: Clarify opt-in WBA access and improve discovery - #627
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
There was a problem hiding this comment.
Risk: Very Low. Approved.
The change is limited to public documentation and sidebar order:
browsers/bot-detection/overview.mdx,stealth.mdx, andweb-bot-auth.mdxupdate copy about opt-in Web Bot Auth access and add cross-links. No code samples, APIs, or runtime behavior change.docs.jsonmoves the existing Bot Anti-Detection navigation group from Advanced to the start of Intermediate. The same page paths stay in place; URLs are unchanged. The JSON still parses.
No application logic, auth, permissions, infrastructure, or schema changes. No CODEOWNERS file, so code owner review is not required. No prior approval on this PR.
Sent by Cursor Automation: Assign PR reviewers
| [Web Bot Auth (WBA)](https://datatracker.ietf.org/doc/html/draft-meunier-web-bot-auth-architecture) lets your browser agent cryptographically sign requests so participating websites can verify its identity. Sites that recognize and allow that identity can let your agent continue with fewer bot challenges and interruptions. | ||
|
|
||
|  | ||
| We offer **KERNEL's WBA token** as an **opt-in feature**, enabled selectively on request for **Startup Plan and Enterprise Plan customers**. It's not enabled by default. |
There was a problem hiding this comment.
Plan details in page intro
Low Severity
The frontmatter description and the paragraph before Request WBA access include plan gating and how to request the managed token. Those details belong in that subsection so the intro stays a high-level orientation on what WBA is.
Triggered by learned rule: Keep page descriptions and intros high-level — push details into subsections
Reviewed by Cursor Bugbot for commit 01a39b5. Configure here.
There was a problem hiding this comment.
Risk: Very Low. Re-checked after the branch update. Existing approval stands; not approving again.
The pull request diff against main is still documentation and sidebar order only:
browsers/bot-detection/overview.mdx,stealth.mdx, andweb-bot-auth.mdxchange copy about opt-in Web Bot Auth access and add cross-links. No code samples, APIs, auth logic, or runtime behavior change.docs.jsonmoves the existing Bot Anti-Detection group from Advanced to the start of Intermediate. The same page paths stay in place.
The new commit (9397bfb) only merges main into this branch. Those files are already on main and are not part of this pull request’s unique diff. Risk does not increase, so the prior approval is left in place.
No CODEOWNERS file is present, so code owner review is not required.
Sent by Cursor Automation: Assign PR reviewers
dprevoznik
left a comment
There was a problem hiding this comment.
LGTM - left one suggestion, but otherwise 🚢 it
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 9397bfb. Configure here.
| ### [Web Bot Auth (WBA)](/browsers/bot-detection/web-bot-auth) | ||
| WBA lets your agent sign requests with a verifiable identity. Participating websites that recognize and allow that identity can reduce bot challenges and interruptions in your workflows. | ||
|
|
||
| **KERNEL's WBA token is opt-in**, enabled selectively on request for **Startup Plan and Enterprise Plan customers**. It's not enabled by default. [Request WBA access](/browsers/bot-detection/web-bot-auth#request-wba-access) to use our bot identity. Each site still controls access; WBA doesn't replace login or guarantee that a site will allow your agent. |
There was a problem hiding this comment.
WBA access policy duplicated
Low Severity
The overview and stealth pages restate WBA opt-in rules, plan eligibility, and access caveats instead of briefly pointing to the canonical Request WBA access section. Those details can drift if the request process changes.
Additional Locations (1)
Triggered by learned rule: Single source of truth — no deep content duplication across pages
Reviewed by Cursor Bugbot for commit 9397bfb. Configure here.
Co-authored-by: Daniel Prevoznik <danny@onkernel.com>
There was a problem hiding this comment.
Risk: Very Low. Re-checked after the latest commit. Existing approval stands; not approving again.
The new commit (69e885e) changes one word in browsers/bot-detection/web-bot-auth.mdx: “automate” to “access” in the request-access sentence. The rest of the pull request is unchanged and still limited to public documentation and sidebar order:
overview.mdx,stealth.mdx, andweb-bot-auth.mdxupdate copy about opt-in Web Bot Auth and add cross-links. No code samples, APIs, auth logic, or runtime behavior change.docs.jsonmoves the existing Bot Anti-Detection group from Advanced to the start of Intermediate. The same page paths stay in place.
Risk does not increase, so the prior approval is left in place. No CODEOWNERS file is present, so code owner review is not required.
Sent by Cursor Automation: Assign PR reviewers




Description
The WBA guide leads with a test-key extension tutorial and doesn't explain who can request the managed WBA token. Add WBA to the title and description, lead with selective opt-in access for Startup and Enterprise plans, and link to the access instructions from the anti-detection overview and stealth guide.
Explain how verifiable identity can reduce challenges and retries on participating sites while preserving site access policies. Keep the test-key and own-key instructions as separate options. Move the complete Bot Anti-Detection navigation group from Advanced to the start of Intermediate without changing page URLs.
Testing
mint broken-linkspasses.mint devstarts; all three edited pages return HTTP 200 with the new content.git diff main...HEAD --checkpasses; full diff reviewed.Existing SDK examples are unchanged and were not executed. Search indexing will occur after publication; hosted search wasn't tested locally.
Implementation checklist
No sample app, CLI, or API changes.
Note
Low Risk
Documentation and navigation-only changes with no runtime, API, or SDK behavior impact.
Overview
Documentation updates clarify KERNEL’s Web Bot Auth (WBA) token as a selective, opt-in capability for Startup and Enterprise customers (not default, not automatic with stealth), with a new Request WBA access flow and cross-links from the bot-detection overview and stealth pages.
The WBA guide is reframed to lead with managed-token access and benefits (verifiable identity, fewer challenges on participating sites, site policy limits), while keeping test-key and bring-your-own-keys paths and noting that the public test key does not enable KERNEL’s production identity.
docs.jsonmoves the full Bot Anti-Detection section (including nested Proxies and WBA) from Advanced to the start of Intermediate for easier discovery; page URLs are unchanged.Reviewed by Cursor Bugbot for commit 69e885e. Bugbot is set up for automated code reviews on this repo. Configure here.