I-D Action: draft-mcgraw-httpapi-agent-budget-03.txt

[email protected] Thu, 23 Jul 2026 04:59:52 -0700
Newsgroups gmane.ietf.announce
Message-ID <178480799260.526408.3993471831398473402@dt-datatracker-d4d6ff9d9-ql5mb>
Internet-Draft draft-mcgraw-httpapi-agent-budget-03.txt is now available.

   Title:   The Delegation HTTP Authentication Scheme for Request-Bound Authority
   Author:  John Paul McGraw, Jr.
   Name:    draft-mcgraw-httpapi-agent-budget-03.txt
   Pages:   43
   Dates:   2026-07-23

Abstract:

   Delegated software requesters increasingly make HTTP requests that
   spend, consume, disclose, mutate, invoke, or actuate on behalf of
   human or organizational principals.  Existing HTTP authentication
   mechanisms indicate whether a requester holds a credential.
   RateLimit fields communicate server-advertised quota and current
   service-limit information.  HTTP Message Signatures can protect
   selected components of an HTTP message.  None of these mechanisms
   directly defines a common origin-server challenge for a requester to
   present verifiable, bounded authority from its principal before the
   server performs protected processing.

   This document defines the "Delegation" HTTP authentication scheme,
   response semantics for delegated-authority challenges using existing
   HTTP status codes and Problem Details, the Delegation-Proof HTTP
   field, and a COSE/CBOR proof carriage model for request-bound
   delegated authority.  The initial authority profile is the Budget
   profile, which uses a CBOR/COSE Budget-Attestation envelope to prove
   bounded authority to spend, consume metered service units, or commit
   bounded resources.  The mechanism is algorithm-agile; the initial
   cose-ml-dsa proof profile uses existing JOSE and COSE serializations
   for ML-DSA, with ML-DSA-65 as the baseline algorithm and ML-DSA-87
   available as a high-assurance deployment policy option.  A dedicated
   4NN Delegated Authority Required status code remains an open design
   question for HTTP Working Group review; this revision does not depend
   on that status code and does not define payment semantics.  This
   revision also defines a mandatory-to-implement preflight flow for
   large proof profiles so that GET and HEAD requests do not depend on
   request content, and so that requests with application
   representations do not need to multiplex the application body and the
   proof body in a single content stream.

   For implementation experience, this individual draft also includes
   the initial Budget authority profile.  The HTTP authentication
   scheme, status-code semantics, Problem Details members, and field-
   carriage rules are intentionally separable from the COSE/CBOR Budget
   profile.  If a Working Group chooses to progress the HTTP mechanism
   independently, the Budget authority profile can be moved to a
   companion profile document without changing the Delegation challenge
   semantics defined here.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-mcgraw-httpapi-agent-budget/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-mcgraw-httpapi-agent-budget-03.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-mcgraw-httpapi-agent-budget-03

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]