Skip to main content Skip to sidebar

KittenProxy

Info
The internet was created for one mystical purpose: sharing cat photos. These days it is flooded with bots instead. KittenProxy is a small step toward giving control back to the cats. Meow.

KittenProxy is a secure filtering and caching proxy that provides safe and policy-controlled internet access for AI and ML bots.

Purpose

KittenProxy sits between automated AI/ML agents and the public internet, enforcing access policies and caching responses to reduce redundant load on origin servers.

Identification

All outbound requests send a predefined User-Agent header so operators can recognize and manage traffic from this proxy:

Mozilla/5.0 (compatible; kittenproxy/1.0; +https://blog.vitalvas.com/page/kittenproxy/)

Request signing

Every outbound request is cryptographically signed using HTTP Message Signatures (RFC 9421 ), so site operators can verify that traffic genuinely originates from KittenProxy rather than a spoofed User-Agent. This is the authoritative way to identify the proxy.

Requests carry the standard Signature and Signature-Input headers. The signature uses the Ed25519 algorithm, and Signature-Input identifies the signing key through its keyid and the covered components. The identity of the proxy is advertised as:

signature_agent: https://webproxy.vitalvas.com

The Ed25519 public keys used for verification are published as a JWKS document at the signature directory, served with content type application/http-message-signatures-directory+json:

https://webproxy.vitalvas.com/.well-known/http-message-signatures-directory

The directory response is itself signed, so verifiers can confirm the key set has not been tampered with.

Rate limiting

All outbound requests are rate-limited to a maximum of 10 requests per second (RPS) per destination domain name and source IP. This limit is applied independently for each domain to avoid overloading any single origin.

Outbound traffic originates from no more than 32 source IP addresses in total (IPv4 and IPv6 combined).

Caching

Visited pages are cached with a flexible policy derived from the response content type and status code. Only responses with a 200 OK status are cached; any other status code (redirects, client errors, server errors) is never cached and is always fetched fresh.

Built with

Contact

For questions about traffic from this proxy, email bot@vitalvas.com .