Reddit builder maigus_ayneha releases the Windi spec and reference implementation proposing a websiteβagent access contract β Web Bot Auth trust tiers, structured RFC 9457 denials, and per-access audit logging β as the middle path between blocking agents and open access; adoption by sites or agent harnesses resolves whether it becomes a real governance layer or a stale draft.
state: watchingheat: lowuncertainty: mediumconvergesscott: highagent-web-access web-bot-auth agent-governance
What is this?
Windi is a proposed open contract between websites and AI agents authored by Reddit user maigus_ayneha (GitHub: maigus223, copyright "(c) 2026 MAIGUS") that ships a complete spec and Node.js/TypeScript reference implementation. It builds on the emerging IETF Web Bot Auth standard (HTTP Message Signatures RFC 9421, Ed25519 keys, JWKS directories β backed by Cloudflare, AWS, Akamai, OpenAI, with an IETF working group chartered in 2026) but adds its own governance layer: Web Bot Auth trust tiers, structured RFC 9457 problem-detail denials, and per-access audit logging. The case tracks whether adoption by sites or agent harnesses turns this into a real governance layer or leaves it a stale draft; current signals are quiet (Reddit post ~0 upvotes, <10 comments, no visible GitHub forks/stars, no IETF or vendor uptake), though new measured evidence shows 7 of 16 subreddits pre-blocking agent accounts, validating the access-denial problem Windi addresses. The web snippets cover the broader Web Bot Auth standard well but do not mention the Windi spec by name, so the Windi-specific design (trust tiers, RFC 9457 denials, audit logs) is grounded only in the case's own evidence.
Why it matters to Scott
A third-party builder independently ships the access-contract middle path Scott's Agent Addressability framework argues for β explicit trust tiers, machine-readable RFC 9457 denials, and per-access audit logs as a delegation surface. The measured evidence (7/16 subreddits pre-blocking agents) validates the problem his Governance Stack diagnoses: missing decision-time authority infrastructure. Directly implementable on his MCP IP Wiki connector (dev:project.mcp-ip-wiki) as a concrete Web Bot Auth profile.
ip:framework.agent-addressabilityip:framework.agent-provenance-stackip:framework.the-governance-stackdev:project.mcp-ip-wikiip:concept.delegation-surfaceip:source.agent-addressability-ebookip:source.agent-provenance-stackip:source.the-governance-stackradar:sierra-personal-agent-protocolradar:shelf-protocol-agent-commerce-permissionsradar:aph-agent-notarization-protocolradar:agent-handoff-protocol-adoptionradar:agentgate-signed-agent-receiptsradar:agenttrust-portable-execution-recordsradar:aether-agent-commerce-protocolradar:canon-a-agent-communication-language
queries asked of Scott's wikis
- agent-addressability delegation surface and website-agent contracts
- provenance-stack identity-to-execution chain for agent access
- governance-stack decision-time authority layer for agent permissions
- mcp-ip-wiki-connector implementation of agent access contracts
- open-weights-sovereignty model sovereignty and agent identity standards
- local-inference-economics agent authentication and access control
Measured heat
now 0 pts/hpeak 2 pts/hcomments 0/hpeers p15momentum: steady2 platformsage 290h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion
How the heat travelled
pace: p30 vs 1188 stories at the 168h mark (now 290h old) β ahead of addom-local-coding-harness (1.5x), behind agentsec-static-config-auditing (0.8x)
Evidence (3) β β canonical anchor
Interpretation history
2026-10-09T08:10:10Z
grounded: converges/high β A third-party builder independently ships the access-contract middle path Scott's Agent Addressability framework argues for β explicit trust tiers, machine-read
2026-10-09T07:57:01Z
New measured evidence (7/16 subreddits pre-blocking agent accounts) substantively validates the access-denial problem Windi addresses, but adoption by sites or agent harnesses remains the sole unresolved gate β no community traction, no independent implementations, no standards-body signals yet.
2026-10-09T04:52:45Z
evidence attached: reddit.post.1x188eh β Measured data showing 7/16 subreddits pre-blocking agent accounts is direct evidence for the agent-access problem the case tracks.
2026-10-01T21:48:44Z
origin walked (opencode/cheap-glm, conf 0.85): anchor reddit.post.1wv9dll -> echo.github.7417b2138b by maigus223 (individual GitHub user; spec copyright line reads "(c) 2026 MAIGUS")
2026-10-01T20:54:14Z
grounded: converges/high β A third-party builder independently ships the access-contract middle path Agent Addressability argues for β explicit trust tiers and machine-readable RFC 9457 d
2026-10-01T20:46:48Z
case created β First-party spec plus working implementation addresses a live gap no open case covers, with a cleanly resolvable adoption claim despite quiet engagement.
Decision trace
- 10-09 19:18attention_routeThe editor compared this story and chose to keep watching.
- 10-09 19:10attention_candidatematerial_reprice
- 10-09 19:10repriceNew measured evidence (7/16 subreddits pre-blocking agent accounts) substantively validates the access-denial problem Windi addresses, but adoption by sites or agent harnesses remains the sole unresol
- 10-09 19:10groundA third-party builder independently ships the access-contract middle path Scott's Agent Addressability framework argues for β explicit trust tiers, machine-readable RFC 9457 denials, and per-acce
- 10-09 18:08attention_communicatedBuilder maigus_ayneha releases spec and Node/TS reference implementation for a middle path between blocking agents and open access: sites declare offerings, agents get trust tiers (anonymous/verified/
- 10-09 18:08attention_routeFurther reading for 6 PM briefing: Scott can evaluate adoption potential and integrate into his MCP IP wiki connector. Already flagged in earlier heads-up; include for completeness.
- 10-09 16:36attention_routeIncluded in 07:00 briefing as previously flagged high-relevance development; Scott can evaluate adoption potential and integrate into his MCP IP wiki connector before the briefing.
- 10-09 15:58attention_routeNew, high-relevance spec that independently implements Scott's agent addressability and governance stack primitives. He can evaluate adoption potential and integrate into his MCP IP wiki connecto
- 10-09 15:52attention_candidateattach
- 10-09 15:52attachMeasured data showing 7/16 subreddits pre-blocking agent accounts is direct evidence for the agent-access problem the case tracks.
- 10-09 15:46propose_attachMeasured data showing 7/16 subreddits pre-blocking agent accounts is direct evidence for the agent-access problem the case tracks.
- 10-02 07:48promote_anchororigin walk conf 0.85
- 10-02 06:54groundA third-party builder independently ships the access-contract middle path Agent Addressability argues for β explicit trust tiers and machine-readable RFC 9457 denials instead of blanket blocking or sc
- 10-02 06:46createFirst-party spec plus working implementation addresses a live gap no open case covers, with a cleanly resolvable adoption claim despite quiet engagement.