AIFeed
English Β· Bahasa Indonesia Β· δΈζ
Signed content permissions for the AI web.
Declare, sign, and revoke what AI agents may do with your content β and let agents prove it.
βΆ Watch: How AIFeed stops web scraping waste
Website Β·
Protocol flow Β·
Benchmark Β·
Complete guide Β·
Paper (PDF)
1-Minute Quickstart
Publisher side β sign what agents may do with your content:
npx aifeed keygen --out .aifeed
npx aifeed site build ./public --domain example.com \
--key .aifeed/aifeed-private.pem --llms --inject
npx aifeed validate ./public --domain example.com
Prefer zero config? npx aifeed init --domain example.com --dir ./site creates the keys,
a signed manifest, and the DNS/host setup guide in one step.
Agent side β verify any domain in 3 lines:
npm install @aifeed/verify
const { verifyRemote } = require('@aifeed/verify');
const out = await verifyRemote('example.com');
console.log(out.result, out.anchor.status);
TypeScript: import { verifyRemote } from '@aifeed/verify';
Where to go next: Why AIFeed? Β· agent quickstart Β·
publisher AI guide Β· Studio publisher app Β·
npm: aifeed CLI Β·
@aifeed/verify
Why AIFeed?
AI agents now drive a large and growing share of web traffic, but the signals that say
what they may do are unsigned text files. Anyone can edit them, nothing binds them to
a domain, and there is no way to revoke them. The asymmetry is measurable:
- 1.9 billion crawls ignored
robots.txt rules in a single half-year (one vendor).
- A 70,900 : 1 crawl-to-referral ratio was measured for a major AI provider.
- AI bots averaged 4.2 % of HTML requests in 2025, peaking at 6.4 %.
AIFeed replaces "please respect this file" with a cryptographically verifiable
declaration, plus lean agent-ready content that cuts cost on both sides.
How it works
- Generate an Ed25519 key pair β the private key never leaves the origin.
- Publish a signed manifest at
/.well-known/ai.json: per-use permissions
(training, retrieval, quote, β¦), crawl limits, license, revision.
- Anchor the key in DNS (
_aifeed TXT) so a manifest cannot be spoofed by another
domain.
- Agents verify the chain β TLS β domain β signature (JCS + Ed25519) β DNS anchor β
and re-check a multi-signature revocation registry on every use.
- Rotate keys safely β announce the successor with an old-key-signed directive (plus
an advisory DNS
pk2 cross-check), keep a bounded overlap, cut over, then revoke the
old key permanently. Runbook: docs/rotation.md.
- Serve lean content under one of two profiles (below), with a signed delta index
so unchanged pages cost 0 bytes.
For AI agents: the check-first guide (discovery β verification β permission
decisions β delta β failure handling) is in
docs/agent-quickstart.md,
with a runnable example at
examples/agent/compliant-agent.js.
Verify from other stacks
Independent Python package (standard library only):
from aifeed import verify
report = verify.verify_directory('./my-site', domain='example.com')
print(report['result'], report['errors'])
Prefer the repository? The same CLI is here (zero dependencies, Node β₯ 20):
cd aifeed-protocol
node bin/cli.js keygen --out keys/
node bin/cli.js validate https://example.com
node bin/cli.js site build ./public --domain example.com --key keys/aifeed-private.pem
Two content profiles
| Profile | Media type | Extension | Notes |
|---|
| AIFeed Markdown (native) | text/aifeed+markdown | .aifeed.md | In-band signed policy block, token budget, translation alternates, triage metadata |
| MAKO (compatibility) | text/mako+markdown | .mako.md | External MAKO trust profile, served from the same signed bytes with its own signature context |
Dual-stack origins serve both; cross-format replay is rejected by design.
Measured results
All numbers are reproducible from committed artifacts (npm run bench:mako,
npm run bench:enforcement); the test environment is a single machine on loopback
networking with a synthetic 60-page corpus. Honest baseline included.
| What | Result | Label |
|---|
| Conversion to markdown profiles vs HTML | β68.83 % transferred bytes | measured |
| Delta consumption (10 % pages changed) | β95.73 % vs HTML crawl | measured |
| Publisher egress bytes / CPU / peak connections | β55.19 % / β56.23 % / β88.24 % | measured (simulation) |
| AI-side received bytes (all profiles / compliant client) | β54.84 % / β72.93 % | measured (simulation) |
| Unchanged pages skipped | 14 of 18 | measured (simulation) |
| Signature verification cost | 0.70 ms / page | measured |
The 30-day live pilot has not run yet; projections per 1,000 tenants are labeled as
model extrapolations, and vendor claims of up to 94 % token reduction require semantic
summarization this project does not perform automatically.
What's in this repository
| Path | Contents |
|---|
lib/ + bin/ | Zero-dependency reference implementation and CLI |
packages/ + clients/python/ | Published packages: CLI (aifeed), SDK (@aifeed/verify), MCP server, build plugins (@aifeed/frameworks), PyPI aifeed verifier |
conformance/ | Conformance vectors: 34 manifest Β· 39 MAKO Β· 11 AIFeed Markdown |
wp-plugin/ | WordPress plugin: signed manifest, AIFeed Markdown + MAKO dual-stack, /llms.txt |
spec/ | Specifications EN/ID: manifest v0.1/v0.2, AIFeed Markdown v1.0 |
schema/ | JSON Schemas for manifests, signatures, AIFeed Markdown, MAKO |
paper/ | Preprint: LaTeX source, PDF, claim ledger, arXiv bundle |
docs/ | Agent quickstart, deploy and namespace guides, Indonesian project notes |
studio/ | Zero-dependency local publisher app: crawl, declare, build, verify, export, and rotate |
docs/REFERENCE.md | Reference implementation details, what gets verified, CLI quickstart |
Documentation
Status
- Release
1.0.0-draft β the specifications are not frozen yet. Wire versions:
manifest 0.1/0.2, AIFeed Markdown 1.0, MAKO 0.2.
- Conformance: 34 manifest + 39 MAKO + 11 AIFeed Markdown vectors, executed by
independent JavaScript and Python verifiers, plus PHP differential fixtures, 90,000+
fuzz executions, and a WordPress end-to-end test.
- Not claimed: external cryptographic review and a live pilot (both pending);
origin+DNS compromise is undetectable on first contact.
Specifications CC BY 4.0 Β· reference code and plugin MIT Β· vectors CC0.
Contact: contact@aifeed.md β security reports per
SECURITY.md.