# IOTA Web Guardian - Roadmap 2026 **Authors:** Paolo Alberti, Niccolò Normani **Last Updated:** April 28, 2026 **Version:** 1.0 --- # Horizon 0 - 2026 ## Medium Goal - Agent Detector Plugin **Timeline:** June → August 2026 **Focus:** Ship a free, production-ready WordPress plugin with AI bot detection (no blockchain, no payments) ### Core Functionality The plugin focuses on **one job done extremely well**: detecting AI bots and giving creators control. **Features:** - **Detection Engine** - JA4 TLS fingerprinting (headless browsers vs real Chrome) - User-Agent heuristics with fallback rules - Behavioral signals (missing CSS/JS fetch, request rate patterns) - Honeypot link mechanism for trap-based detection - **Creator Controls** - Per-bot granular control: block, allow, or log - Activity dashboard in WordPress admin - Which AI bots visited - Request frequency and page patterns - Detection confidence scores - **Allowlist Management** - Built-in verified allowlist (Googlebot, Bingbot, Common Crawl via reverse DNS) - Publisher UI to extend allowlist - "I am human" accessibility path for false positives - **Distribution & Onboarding** - Listed on WordPress.org Plugin Directory - 60-second setup: install → email confirm → first bot blocked - Zero blockchain jargon in UI - Works on shared hosting (no infrastructure changes required) ### Success Criteria - **Target:** 100+ active installs by end of July 2026 - WordPress.org marketplace listing live - Detection accuracy: >90% on known AI crawlers - False positive rate: <2% (measured via telemetry) - Average setup time: <60 seconds ### Distribution Channels - WordPress Plugin Directory (organic search) - ProductHunt launch - HackerNews ("Show HN" post) - IndieWeb, IndieHackers communities - Direct outreach to WordPress creator newsletters - Twitter/X threads targeting creators affected by AI scraping ### Technical Architecture - WordPress-native (no DNS changes, no external services) - Detection at plugin layer (PHP + optional sidecar for advanced fingerprinting) - Opt-in telemetry for continuous improvement - Structured logging with reason codes for every block/allow decision --- ## Maximum Goal - Non-Custodial IOTA Web Guardian **Timeline:** August → December 2026 **Focus:** Introduce optional payment layer on IOTA for creators who want to monetize AI access through a non custodial approach (not E2E yet, which would be horizon 1) ### New Capabilities Building on Phase 1's detection foundation, add the economic layer: **Monetization Features:** - **x402 Payment Protocol** - AI agents receive 401 challenge on protected content - Compliant agents present Verifiable Presentation (VP) signed by DID - Payment processed on IOTA L1 → Guardian JWT issued → 200 OK content - **Web2-First Onboarding (Custodial Mode)** - Email/Google signup → wallet provisioned by partner custodian (e.g., Magic Labs) - DID generation and binding happen invisibly orchestrated by our solution - Private Keys are managed through KMS integration (i.e. AWS, HashiVault Corp) - Verifiable Credentials (VCs) are stored by us - Verifiable Presentations are signed by us based on the corresponding DID Private Keys - The payment is performed with the hosted non-custodial wallet in Magic Labs - Publisher dashboard shows balance in EUR/USD, not IOTA tokens - Fiat off-ramp integrated (Transak, Ramp, MoonPay, or SEPA) - One-click withdrawal to PayPal/Stripe/bank account - **Pricing UI** - Human language: "€0.50 per 1,000 scraper visits" - Suggested presets for blog/news/docs - Advanced view available on demand (DID, blockchain details) ### Security & Anti-Bypass Measures - **VP Replay Prevention** - VP bound to request-specific nonce (timestamp + URL hash) - JWT bound to IP/UA/DID → re-auth on context change - Short TTL (1 hour), nonce rotation - **Sybil Resistance** - Combined per-DID and per-origin rate limiting - Reputation scoring: new DIDs throttled, clean history = fast-lane - **Detection Hardening** - Layered detection: TLS fingerprint + behavioral + optional PoW challenge - Progressive challenge system (invisible to humans, costly for mass scrapers) - Honeypot links, HTTP/2 settings frame fingerprint ### Trade-Off Considerations Based on learnings from Phase 1, evaluate: - **Custodial vs. Non-Custodial Default** - Custodial (recommended by E2E solution): Zero regulatory risk for us, better UX, partner dependency - Non-Custodial: More control, higher complexity for users, higher latency as centralised by a "Web2" approach - **Detection Accuracy vs. False Positives** - Default-permissive policy on first hit (async classification) - Always-available "I am human" path - Dashboard transparency: "X requests rejected, Y% likely human" - **Pricing Model** - Free tier: Detection + blocking (always free) - Pro tier ($9/month): Advanced analytics, allowlist management, priority updates - Revenue share: % of payments processed through monetization layer ### Success Criteria - **10 real pilot publishers** onboarded (non-friends/family) - Each running for 30+ days with shared telemetry - **3 written case studies** with real numbers: - Revenue captured - Scrapers blocked - Uptime and conversion friction - **External validation:** - Public bug bounty program launched - Light external security audit completed (1-week scope) - Public whitepaper: "How We Distinguish Humans from AI Agents" - **End-of-year metrics:** - Active installs, scrapers blocked, EUR redistributed to publishers - p50/p95 latency measurements - Material ready for next funding round ### Demand-Side Enablement - Reference SDK for legitimate AI agents (Claude, OpenAI) calling x402-protected endpoints correctly - Documentation: "How AI companies can pay for content access" - Without credible demand side, system is just a firewall. With it, it becomes a market. --- ## Cross-Cutting Tracks (April → December 2026) ### Track A: Hardening & Measurement **Owner:** Niccolò (lead) **Focus:** Performance, security, observability - Continuous benchmarking pipeline - Stress testing on IOTA Rebased testnet - Public benchmark page (updated quarterly) - SOC 2 compliance roadmap (target 2027 certification) ### Track B: Detection Robustness **Owner:** Niccolò (with external review) **Focus:** Anti-bypass, accuracy - Four attack vector mitigation: 1. Scraper masquerading as browser 2. False positives on humans 3. VP replay/forging 4. Sybil attacks on DIDs - Layered detection: fingerprint + behavior + challenge - Honest framing: "We make bypass non-profitable, not impossible" ### Track C: Web2 Onboarding **Owner:** Paolo (lead) **Focus:** Non-crypto publisher UX - Custodial mode by default (partner integration) - Fiat-denominated pricing and withdrawals - Zero blockchain jargon on first screen - 60-second setup wizard - Whitelabel UI (publisher branding, not ours) ### Track D: Distribution & Proof **Owner:** Paolo + Niccolò (joint) **Focus:** Real publishers, case studies, marketplace - WordPress.org submission (October) - Pilot publisher recruitment (non-friends/family) - Video tutorial (IT + EN, 5-10 min) - FAQ and exit story documentation - Public report: aggregate metrics at year-end --- ## Key Performance Indicators (End of December 2026) | Metric | Target | |--------|--------| | Real publishers onboarded | 10+ | | WordPress.org plugin listing | Live | | Public benchmark (p50/p95/p99) | Published | | Threat model document | Published | | External security audit | Completed | | Detection bypass mitigation | All known vectors non-economic | | Custodial on-ramp partner | ≥1 integrated | | Case studies with real numbers | 3 | | Public whitepaper on detection | Published | --- ## Risks & Mitigation | Risk | Likelihood | Impact | Mitigation | |------|------------|--------|------------| | Bypass discovered after public launch | High | Medium | Bug bounty, fast patching, layered detection | | Custodial partner unavailable/expensive | Medium | High | Evaluate 2 partners in Q2; fallback to non-custodial-only | | Legitimate AI agents don't adopt x402 | Medium | High | Demand-side SDK (Q4), Anthropic/OpenAI outreach | | WordPress.org rejects plugin | Low | Medium | Pre-submission compliance review | | Latency regression on IOTA testnet | Medium | Medium | Continuous benchmarking, fallback paths | | Large publisher requires SOC 2 | Medium | Medium | Compliance roadmap published, 2027 certification target | ## Guiding Principles 1. **Detection as foundation** – If detection breaks, everything breaks. Continuous priority. 2. **Web2 first impression, Web3 underneath** – Publishers shouldn't know DIDs exist unless they want to 3. **Bug bounty as signal** – Even small programs signal openness to scrutiny 4. **Default-permissive on humans** – False positives destroy trust faster than bypass attempts **Prepared by:** Paolo Alberti, Niccolò Normani **For:** IOTA Foundation, project advisors, investor discussions **Status:** Internal review → External sharing # Horizon 1 - 2027 - Full IOTA Web Guardian Full IOTA Web Guardian E2E integration as per hackaton proposal. All wallets and DIDs are custodial and privates.