# Vendor facets — Amazon CloudFront (with AWS WAF Bot Control and edge functions). An edge that # caches, terminates TLS and enforces WAF rules, with an x402 "Monetize" action and site-side Web # Bot Auth verification. None of it produces an artifact the Kin Score reads at 0.22.0: no maps. vendor: cloudfront name: Amazon CloudFront website: https://aws.amazon.com/cloudfront/ areas: - cdn registry_keys: - cloudfront rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: measured summary: >- CloudFront moves no Kin Score check on its own. Its agent features are real but enforcement-side. AWS WAF Bot Control verifies Web Bot Auth signatures from incoming agents and can answer AI bots with an x402 HTTP 402 (the Monetize action, CloudFront only). Neither produces the /.well-known UCP/ACP document agentic_commerce reads or the signing-key directory consent_identity points at. CloudFront Functions and Lambda@Edge can serve anything, but the credit goes to the file the provider writes, not to the edge. features: - id: edge-functions name: CloudFront Functions and Lambda@Edge description: >- Provider-written code at the edge that rewrites requests and responses, sets headers and generates responses. source: https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/edge-functions.html tier: all - id: waf-bot-control name: AWS WAF Bot Control description: >- A managed rule group that labels, verifies, rate-limits or blocks bots, with a targeted level for bots that do not identify themselves. source: https://docs.aws.amazon.com/waf/latest/developerguide/waf-bot-control.html tier: paid - id: web-bot-auth-verification name: Web Bot Auth verification description: >- Bot Control 4.0+ cryptographically verifies AI agents that sign requests with HTTP Message Signatures, and allows verified agents by default. source: https://aws.amazon.com/about-aws/whats-new/2025/11/aws-waf-web-bot-auth-support tier: paid - id: ai-traffic-monetization name: AI traffic monetization (Monetize action, x402) description: >- WAF returns an x402 HTTP 402 Payment Required to AI bots on CloudFront distributions, verifies payment at the edge and serves the content. No extra charge beyond WAF. source: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-waf-ai-traffic-monetization/ tier: paid - id: rate-based-rules name: AWS WAF rate-based rules description: Counts requests per aggregation key over a window and rate-limits groupings over the threshold. source: https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-type-rate-based.html tier: paid maps: [] earns_nothing: - feature: ai-traffic-monetization check: agentic_commerce layer: agent_readiness why: >- agentic_commerce reads a parsing /.well-known/ucp.json or acp.json. The Monetize action is a per-request x402 402 exchange, and the fetched pages describe no discovery document. - feature: web-bot-auth-verification check: consent_identity layer: agent_readiness why: >- This verifies OTHER parties' signed agents. The WebBotAuth/HTTPMessageSignatures pointers point at a key directory that only a bot operator publishes. - feature: rate-based-rules check: rate_limit_signal layer: agent_readiness why: >- The dimension reads RateLimit headers documented in the provider's OpenAPI, or a rate_limits artifact. Rate-based rules enforce limits and the fetched docs describe no standard headers. - feature: edge-functions check: well_known_published layer: composite why: >- A function can serve security.txt or an api-catalog, but the provider writes the document. Any origin could serve the same file. - feature: waf-bot-control check: servers_resolvable layer: composite why: Caching, TLS termination, DDoS absorption and bot filtering change nothing any check reads. out_of_reach: checks: - consent_identity - agentic_commerce - llms_txt_published - well_known_published - mcp_server - protected_resource_metadata - dynamic_client_registration - contract_present note: >- CloudFront ships no managed robots.txt, security.txt, llms.txt, OAuth library or MCP hosting, so every agent-facing artifact is the provider's own work served through it. unscored_practice: - feature: ai-traffic-monetization why: >- x402 payment at the edge is deployed and generally available. 0.22.0 reads only UCP/ACP discovery documents for commerce. surface: agent_readiness: reachable: 0 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://aws.amazon.com/about-aws/whats-new/2025/11/aws-waf-web-bot-auth-support - https://aws.amazon.com/about-aws/whats-new/2026/06/aws-waf-ai-traffic-monetization/ - https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/edge-functions.html - https://docs.aws.amazon.com/waf/latest/developerguide/waf-bot-control.html - https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-type-rate-based.html measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 135 in_baseline: 46 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5170 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' composite_mean: cohort: 47.2 control: 48.0 agent_readiness_mean: cohort: 30.3 control: 32.5 status: measured caveat: >- A cohort delta is association, not cause: customers choose a vendor for reasons that also move their score. Read it beside the capability map, never instead of it. simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 0 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 0.0 p75: 0.0 p90: 0.0 max: 0.0 mean_among_movers: 0.0 agent_readiness_lift: median: 0.0 p75: 0.0 p90: 0.0 max: 0.0 mean_among_movers: 0.0 facet_lift_median_among_movers: {} composite_band_moves: {} agent_readiness_band_moves: {} method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written