Short description of issue
Since 2026-09-29, every request from our Oracle Cloud server (144.24.140.188) to Shopify storefronts gets HTTP 429, even with valid Web Bot Auth signatures; the same requests from a residential IP return 200.
Reproduction steps
- From our server (Oracle Cloud, egress IP 144.24.140.188), send one signed GET to any storefront, e.g.
archiwatch.com/products.json?limit=1 - Headers (Web Bot Auth, RFC 9421, Ed25519, tag=“web-bot-auth”):
User-Agent: Mozilla/5.0 (compatible; WatchMLScraper/1.0; +https://product-scrapper.appweave.tech/bot)
Signature-Agent: sig1="https://product-scrapper.appweave.tech"
Signature-Input: sig1=("@authority" "signature-agent";key="sig1");created;keyid;alg="ed25519";expires;nonce;tag="web-bot-auth" - Result: HTTP 429, retry-after: 60, on the first request, on all ~40 stores, at any time of day.
- The same request from a residential connection returns 200.
Full signed request, signature base and response headers (x-request-id, cf-ray) are in the first reply below.
Additional info
WatchMLScraper is a small inventory crawler for ~40 watch dealers on Shopify: one /products.json pass per store per day, sequential, no checkout/cart/customer data.
Since 2026-09-29 ~20:00 UTC every request from our IP gets 429, with no change on our side and no recovery after 7 days, so it isn’t a rate-limit bucket. Requests are now signed, still 429. We submitted the Web Bot Auth registration form today.
Key directory: https://product-scrapper.appweave.tech/.well-known/http-message-signatures-directory
Bot info: https://product-scrapper.appweave.tech/bot
Egress IP: 144.24.140.188
Similar to Third-party Web Bot Auth crawler receives immediate 429s from OCI but succeeds residentially (also OCI). Could someone check whether our signature verifies on your side, and whether this IP can get signed-bot limits? Happy to send fresh captures.
What type of topic is this
Troubleshooting