tencent cloud

Tencent Cloud EdgeOne

DocumentationTencent Cloud EdgeOneDDoS & Web ProtectionWeb ProtectionRelated ReferencesCarrying the Web Security Detection Result Headers Back to Origin

Carrying the Web Security Detection Result Headers Back to Origin

Download
Focus Mode
Font Size
Last updated: 2026-09-24 10:45:47
AI-Translated

Overview

After the EdgeOne Web Security module identifies request characteristics, it can carry the detection results in the origin-pull request in the form of HTTP request headers. The origin server can directly read the Bot and client risk information in its business logic without calling additional APIs, and then perform secondary actions such as differentiated rate limiting, content degradation, and manual review.
Note:
This feature is being rolled out gradually. If the relevant configuration card does not appear in your account, wait until the product is fully released before configuring it.
This feature is available only for sites in the Enterprise plan.
You must first enable the Bot Management feature corresponding to the header. Only after the module generates detection results will this header be carried in the origin-pull request.
Only HTTPS requests carry the JA3 and JA4 fingerprints. If the domain has enabled Advanced Bot Management but the EO-Bot-Fingerprint header in the origin-pull request is empty, check whether HTTPS access is enabled for the domain.
Compatibility Note: The existing EO-Bot-Tag header is retained with unchanged behavior and is independent of the headers described in this document.

User Guide

1. Log in to the EdgeOne console, go to Service Dashboard in the left sidebar, and click the site to configure under Website Security Acceleration.
2. Click Security > Web Security. The default is a site-level security policy. Click the Domain-level Security Policy tab, then click the target domain to go to its protection policy configuration page, for example, www.example.com.
3. In the General Settings category at the bottom of the policy page, locate the Send Web Security Detection Results to Origin in Request Headers card and click Edit.
4. In the pop-up window, select the headers to be carried on origin-pull.
5. Click Save to save the configuration.

Origin-Pull Request Header Details

The complete format of each header after origin-pull is described below. The sample values are provided only to illustrate the format, and the actual values are subject to the detection results of EdgeOne.

Format Description

All related headers are serialized according to RFC 9651, Structured Field Values for HTTP, with top-level types divided into Dictionary and List. The number of members in each header is not fixed. Parse the headers according to RFC 9651 and do not rely on a fixed field order or fixed number of members.
Top-level Type
Structure
Applicable Headers
Dictionary
Members are in the "key=value" format and separated by commas.
EO-Bot-Fingerprint,EO-Bot-Known-Tool,EO-Bot-Search-Engine,EO-Bot-Source-IDC,EO-Bot-IP-Reputation,EO-Bot-Intelligence,EO-Bot-Botnet-ID
List
Members are attestation instances separated by commas. Each instance consists of a bare value and parameters, with parameters introduced by a semicolon.
EO-Bot-Client-Attestation,EO-Bot-Client-Risk,EO-Bot-User-Risk

Client Fingerprint

EO-Bot-Fingerprint

Carries the client TLS fingerprint. The ja3 and ja4 fingerprints are carried based on the actual detection capability; either one or both of them may be present.
Associated Feature: Advanced Bot Management
Field
Type
Description
ja3
String
TLS client JA3 fingerprint.
ja4
String
TLS client JA4 fingerprint.
EO-Bot-Fingerprint: ja3="d41d8cd98f00b204e9800998ecf8427e", ja4="t13d1516h2_8daaf6152771_02713d6af862"

Bot Management Related Information

EO-Bot-Known-Tool

Carries the category and name of the matched known tool (crawler or automation program).
Associated Feature: Advanced Bot Management > Basic Feature Management (UA Feature Rules)
Field
Type
Description
category_name
String
The category of the matched tool. The value is maintained by the EdgeOne tool signature database, for example, search_engine (search engine).
tool_name
String
Name of the matched tool, for example, Bingbot, GoogleBot, PagePeeker.
EO-Bot-Known-Tool: category_name="search_engine", tool_name="Bingbot"

EO-Bot-Search-Engine

Carries the name of the matched search engine provider.
Associated Feature: Advanced Bot Management > Basic Feature Management (Search Engine Rules)
Field
Type
Description
provider_name
String
Name of the matched search engine provider, for example, 360Spider, DuckDuckBot, GoogleBot.
EO-Bot-Search-Engine: provider_name="360Spider"

EO-Bot-Source-IDC

Carries the names of the IDC and carrier to which the request source IP address belongs.
Associated Feature: Advanced Bot Management > Basic Feature Management (IDC Rules)
Field
Type
Description
idc_name
String
Name of the IDC or carrier, for example, pccw.com.
EO-Bot-Source-IDC: idc_name="pccw.com"

EO-Bot-IP-Reputation

Carries the threat type and confidence level of the request source IP address. The number of members is not fixed, and multiple threat types are carried in parallel when matched.
Associated Feature: Advanced Bot Management > Client Reputation
Field
Type
Description
<threat_type>
String
The field name is the threat type. Values include attacker (network attack), proxy (network proxy), scanner (scanner), account_take_over (account takeover attack), and malicious_bot (malicious Bot).
Value of <threat_type>
String
Confidence level of the corresponding threat type. Values include high (high confidence), medium (medium confidence), and low (low confidence).
EO-Bot-IP-Reputation: proxy="high", account_take_over="medium"

EO-Bot-Intelligence

Carries the risk score and risk level from Bot intelligent analysis.
Associated Feature: Advanced Bot Management > Bot Intelligence
Field
Type
Description
bot_rating
String
Bot rating. Values include evil_bot (malicious Bot request), suspect_bot (suspected Bot request), good_bot (normal Bot request), normal (normal request), and - when the bot rating is unclassified.
EO-Bot-Intelligence: bot_rating="evil_bot"

EO-Bot-Client-Attestation

Carries the verification status and exception reason of the client attestation ticket. When multiple attestation instances exist in the same request, the instances are separated by commas.
Associated Feature: Advanced Bot Management > Client Attestation
Field
Type
Description
token_status
String
Token verification status. Values include valid (token valid), invalid (token invalid), and expired (token expired).
token_exceptions
String
Reason for token verification exception. Multiple exception tags are separated by half-width commas (,). Values include EO-Attest-TokenMissing (the request does not carry the attestation result token), EO-Attest-TokenExpired (the token has expired), and EO-Attest-UsageLimitExceeded (the token has exceeded the usage limit), etc.
EO-Bot-Client-Attestation: attest-0000056382;token_status="expired";token_exceptions="EO-Attest-TokenExpired"

EO-Bot-Client-Risk

Carries the client risk information identified by Client Attestation and human-machine verification.
Associated Feature: Advanced Bot Management > Client Attestation
Field
Type
Description
attester_type
String
Attestation method identifier, generated by combining the attestation provider and attestation option, for example, TC-EO-CAPTCHA. Available attestation providers include EdgeOne human verification, Tencent Cloud Captcha, and Tencent Cloud RCE. The specific value is subject to the configuration in the console under Client Attestation > Attesters.
device_type
String
Client device type that initiates attestation, for example, android.
risk_score
Integer
Client risk score. The value range is 0-100, and a higher score indicates higher risk.
risk_level
String
Client risk level. Values include high (high risk), medium (medium risk), and low (general risk).
risk_details
String
Client risk details. Multiple risk tags are separated by half-width commas (,), for example, EO-App-DataAnomaly (abnormal client data) and EO-App-FPLowConfidence (low confidence in client fingerprint).
EO-Bot-Client-Risk: attest-0000056382;attester_type="TC-EO-CAPTCHA";device_type="android";risk_score=100;risk_level="high";risk_details="EO-App-DataAnomaly,EO-App-FPLowConfidence"

EO-Bot-User-Risk

Carries the user risk information identified by client attestation-account protection.
Associated Feature: Advanced Bot Management > Client Attestation
Field
Type
Description
attester_type
String
Attestation method identifier, generated by combining the attestation provider and attestation option, for example, TC-EO-CAPTCHA. Available attestation providers include EdgeOne human verification, Tencent Cloud Captcha, and Tencent Cloud RCE. The specific value is subject to the configuration in the console under Client Attestation > Attesters.
device_type
String
Client device type that initiates attestation, for example, android.
user_id
String
User account identifier that initiates attestation. The value is the Base64 encoding of the original account representation.
user_operation
String
User operation type, defined by the business in Client Attestation rules. The value is the Base64 encoding of the original operation type.
risk_score
Integer
Account risk score. The value range is 0-100, and a higher score indicates higher risk.
risk_level
String
Account risk level. Values include high (high risk), medium (medium risk), and low (general risk).
risk_details
String
Account risk details. Multiple risk tags are separated by half-width commas (,), for example, EO-Acc-UReqRateE (excessively fast user requests).
EO-Bot-User-Risk: attest-0000056382;attester_type="TC-EO-CAPTCHA";device_type="android";user_id="YWRtaW4=";user_operation="YWNjb3VudC5sb2dpbg==";risk_score=99;risk_level="high";risk_details="EO-Acc-UReqRateE"

Bot Identification Information

EO-Bot-Botnet-ID

Carries the identifier of the network to which the Bot belongs (botnet). Requests belonging to the same Bot network carry the same identifier, allowing the origin server to perform clustering and handling based on this identifier.
Associated Feature: Advanced Bot Management
Field
Type
Description
botnet_id
String
Bot network identifier, for example, 0dad2a4c7f1e93b5c2d84e6f0a1b3c57.
EO-Bot-Botnet-ID: botnet_id="0dad2a4c7f1e93b5c2d84e6f0a1b3c57"


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback