PACT Isn’t Live Yet, But Website Owners Should Still Pay Attention
An new protocol is being developed by Cloudflare and the major web browsers, to help businesses to identify genuine visitors, and not waste server resources on rising bot traffic.
Oops! We could not locate your form.
An new protocol is being developed by Cloudflare and the major web browsers, to help businesses to identify genuine visitors, and not waste server resources on rising bot traffic.
On 22 June 2026, Cloudflare announced something worth flagging to everyone running a website, whether on WordPress or a different platform. It’s a new protocol called PACT (Private Access Control Tokens), being developed alongside Mozilla, Google Chrome, Microsoft Edge, and Shopify.
It’s not live, there’s no plugin to install, no setting to toggle, and nothing to test this quarter. But when Chrome, Firefox and Edge agree to build the same thing at the browser level, it’s worth understanding before it arrives, not after.
Bot traffic has been increasing to record levels, and it has moved to being an infrastructure problem, not just a security one.
Right now, most sites tell humans apart from bots using CAPTCHAs, forced logins, or invasive fingerprinting. All three create friction for real visitors and customers, and come with some real privacy concerns we’ll look at shortly.
PACT is designed to replace that.
A site with strong ‘knowledge of personhood’ (so, one where you’ve logged in, or perhaps a site where you’ve demonstrated a track record of genuine human behaviour) issues your browser an anonymous token. Your browser can then present that token to other sites as proof a human is behind the request, without the token being traceable back to you, and without two uses of it being linkable to each other, Really important from a privacy and tracking standpoint.
In layman’s terms it means there is less friction for real users, without the tracking cost.
It’s worth being specific about why ‘without the tracking cost’ matters, because the three methods of verification that PACT is meant to replace aren’t privacy-neutral:
That last point is the real significance of PACT’s design. Its tokens are built to be anonymous and unlinkable, not just a ‘we promise not to misuse this data’. A site can’t see where you spend a token, another site can’t tie it back to you, and two uses of it can’t be connected. If that holds up in practice, it’s a structurally different privacy position to CAPTCHAs, forced logins, or fingerprinting, rather than just a friendlier-looking version of the same thing.
We build and support a lot of WordPress & WooCommerce sites with checkouts, gated content, contact forms, and membership functionality. On most of those we have had to make an uncomfortable trade-off, adding friction (with CAPTCHAs, logins, etc) to keep bots out, or accept a certain amount of bot traffic, fake form submissions, and inventory-hoarding checkout bots to keep the experience smooth.
Take the example we wrote about last week, where a client’s online store was being flooded with fake PayPal orders and disposable email sign-ups, all from rotating IPs, none of it stoppable with a simple IP block. Cloudflare Turnstile solved it, invisibly checking that a real person was behind each checkout and registration, without adding a puzzle for genuine customers to solve.
That’s exactly the trade-off PACT is aimed at, just one level up the stack. Turnstile proves personhood at the point of one site. PACT would let that proof travel with the visitor’s browser, so other sites can trust it too, without CAPTCHAs, without forced logins, and without the token being traceable back to the individual. If it lands the way it’s being pitched, it could mean:
This is the bit that’s easy to miss in the coverage. PACT proves a human is present but it says nothing about whether an autonomous agent acting on someone’s behalf is allowed to be there, or what it’s allowed to do.
That distinction is already a live industry problem, not a hypothetical one. A recent Juniper Research study named trust, not technology, as the single biggest barrier to agentic commerce adoption. Amex built a dedicated developer kit this year specifically because merchant checkout systems were flagging legitimate AI-agent purchases as bot fraud. And on the regulatory side, it’s genuinely unresolved whether an AI agent acting on a customer’s behalf satisfies existing consumer-protection authorisation rules, which leaves merchants exposed if that purchase is later disputed.
That’s exactly why Visa, Mastercard, and Amex are all building separate ‘Trusted Agent Protocol’ or ‘know your agent’ layers this year, cryptographically signing and registering agents so a merchant can tell a legitimate one from a scraper or a fraud attempt.
PACT and these frameworks are solving adjacent but different problems. PACT says a human exists somewhere behind this traffic, whilst the agent frameworks say this specific agent is who it claims to be and is authorised to do this specific thing. A site will likely need both, not one instead of the other.
Most site owners have never had to separate these two questions, because until recently, ‘a visitor’ and ‘a human’ were mostly the same thing. That’s no longer a safe assumption, and for WooCommerce and other eCommerce stores specifically, it’s worth watching how the payment networks’ agent frameworks interact with whatever checkout provider you’re on, well before agent-initiated purchases start showing up in your order data.
Nothing needs to be implemented today, because there’s nothing to implement. But it’s a good moment to:
We’ll be tracking PACT as it moves toward standardisation and will flag it again once there’s something concrete to act on. In the meantime, if you want a proper look at where bot traffic and friction are costing you conversions right now, that’s a conversation worth having regardless of what Cloudflare ships next.
Bot is the umbrella term for any automated software making requests to a website – search crawlers (Googlebot), scrapers, spam scripts, DDoS traffic, AI training crawlers (GPTBot), and so on. Bots typically follow fixed rules or scripts like crawl this URL, submit this form, repeat.
Agent (in the ‘agentic AI’ sense) is a bot with a goal and the autonomy to figure out how to reach it. Instead of ‘fetch these 500 URLs’, it’s ‘book me a flight under £300 that lands before 6pm’. The agent then reasons through search, comparison, and checkout steps on its own, adapting as it goes

If you’d like to learn more about our WordPress & WooCommerce Support & Maintenance plans, drop us an email or give James a call.
Our plans provide a holistic solution to your website’s performance, reliability and security, and are inclusive of premium tools and services.