2026-10-11 16:37 UTC

Reddit builder maigus_ayneha releases the Windi spec and reference implementation proposing a website–agent access contract β€” Web Bot Auth trust tiers, structured RFC 9457 denials, and per-access audit logging β€” as the middle path between blocking agents and open access; adoption by sites or agent harnesses resolves whether it becomes a real governance layer or a stale draft.

state: watchingheat: lowuncertainty: mediumconvergesscott: highagent-web-access web-bot-auth agent-governance

What is this?

Windi is a proposed open contract between websites and AI agents authored by Reddit user maigus_ayneha (GitHub: maigus223, copyright "(c) 2026 MAIGUS") that ships a complete spec and Node.js/TypeScript reference implementation. It builds on the emerging IETF Web Bot Auth standard (HTTP Message Signatures RFC 9421, Ed25519 keys, JWKS directories β€” backed by Cloudflare, AWS, Akamai, OpenAI, with an IETF working group chartered in 2026) but adds its own governance layer: Web Bot Auth trust tiers, structured RFC 9457 problem-detail denials, and per-access audit logging. The case tracks whether adoption by sites or agent harnesses turns this into a real governance layer or leaves it a stale draft; current signals are quiet (Reddit post ~0 upvotes, <10 comments, no visible GitHub forks/stars, no IETF or vendor uptake), though new measured evidence shows 7 of 16 subreddits pre-blocking agent accounts, validating the access-denial problem Windi addresses. The web snippets cover the broader Web Bot Auth standard well but do not mention the Windi spec by name, so the Windi-specific design (trust tiers, RFC 9457 denials, audit logs) is grounded only in the case's own evidence.

Why it matters to Scott

A third-party builder independently ships the access-contract middle path Scott's Agent Addressability framework argues for β€” explicit trust tiers, machine-readable RFC 9457 denials, and per-access audit logs as a delegation surface. The measured evidence (7/16 subreddits pre-blocking agents) validates the problem his Governance Stack diagnoses: missing decision-time authority infrastructure. Directly implementable on his MCP IP Wiki connector (dev:project.mcp-ip-wiki) as a concrete Web Bot Auth profile.
ip:framework.agent-addressabilityip:framework.agent-provenance-stackip:framework.the-governance-stackdev:project.mcp-ip-wikiip:concept.delegation-surfaceip:source.agent-addressability-ebookip:source.agent-provenance-stackip:source.the-governance-stackradar:sierra-personal-agent-protocolradar:shelf-protocol-agent-commerce-permissionsradar:aph-agent-notarization-protocolradar:agent-handoff-protocol-adoptionradar:agentgate-signed-agent-receiptsradar:agenttrust-portable-execution-recordsradar:aether-agent-commerce-protocolradar:canon-a-agent-communication-language
queries asked of Scott's wikis
  • agent-addressability delegation surface and website-agent contracts
  • provenance-stack identity-to-execution chain for agent access
  • governance-stack decision-time authority layer for agent permissions
  • mcp-ip-wiki-connector implementation of agent access contracts
  • open-weights-sovereignty model sovereignty and agent identity standards
  • local-inference-economics agent authentication and access control

Measured heat

now 0 pts/hpeak 2 pts/hcomments 0/hpeers p15momentum: steady2 platformsage 290h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-29 14:00⭐ origin echo-reconstructedREADME: "A proposed open contract between websites and AI agents, with a small reference implementation in Node.js/TypeScript." β€” "Websites
maigus223 (individual GitHub user; spec copyright line reads "(c) 2026 MAIGUS") on github (echo) Β· attributed from reddit.post.1wv9dll
β€”
10-01 19:49first on r/ClaudeAI Β· published Β· +53.8hWindi: an experimental open contract between websites and AI agents (spec + Node/TS reference implementation, built with Claude)
maigus_ayneha
β€”
10-09 01:12first on r/artificial Β· published Β· +227.2hThe agent-access problem, measured: 7 of 16 subreddits had already blocked one agent account before it posted anything
lulzxdxdxd
β€”
10-01 19:49amplified on r/ClaudeAI πŸ‘‘reddit.post.1wv9dll
maigus_ayneha
peak 1 Β· 4 comments Β· 70% of case engagement
10-09 01:12amplified on r/artificialreddit.post.1x188eh
lulzxdxdxd
peak 0 Β· 2 comments Β· 27% of case engagement
10-01 20:20our radar first saw it Β· +54.3hdiscovery anchor: reddit.post.1wv9dllβ€”
pace: p30 vs 1188 stories at the 168h mark (now 290h old) β€” ahead of addom-local-coding-harness (1.5x), behind agentsec-static-config-auditing (0.8x)

Evidence (3) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditWindi: an experimental open contract between websites and AI agents (spec + Node/TS reference implementation, built with Claude)
ClaudeAI
maigus_ayneha04
🟧 echo.github ⭐README: "A proposed open contract between websites and AI agents, with a small reference implementation in Node.js/TypeScript." β€” "Websites maigus223 (individual GitHub user; spec copyright line reads "(c) 2026 MAIGUS")β€”β€”
🟠 redditThe agent-access problem, measured: 7 of 16 subreddits had already blocked one agent account before it posted anything
artificial
lulzxdxdxd02

Interpretation history

Decision trace