I-D Action: draft-mcgraw-httpapi-agent-budget-03.txt
[email protected] Thu, 23 Jul 2026 04:59:52 -0700
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178480799260.526408.3993471831398473402@dt-datatracker-d4d6ff9d9-ql5mb> |
Internet-Draft draft-mcgraw-httpapi-agent-budget-03.txt is now available. Title: The Delegation HTTP Authentication Scheme for Request-Bound Authority Author: John Paul McGraw, Jr. Name: draft-mcgraw-httpapi-agent-budget-03.txt Pages: 43 Dates: 2026-07-23 Abstract: Delegated software requesters increasingly make HTTP requests that spend, consume, disclose, mutate, invoke, or actuate on behalf of human or organizational principals. Existing HTTP authentication mechanisms indicate whether a requester holds a credential. RateLimit fields communicate server-advertised quota and current service-limit information. HTTP Message Signatures can protect selected components of an HTTP message. None of these mechanisms directly defines a common origin-server challenge for a requester to present verifiable, bounded authority from its principal before the server performs protected processing. This document defines the "Delegation" HTTP authentication scheme, response semantics for delegated-authority challenges using existing HTTP status codes and Problem Details, the Delegation-Proof HTTP field, and a COSE/CBOR proof carriage model for request-bound delegated authority. The initial authority profile is the Budget profile, which uses a CBOR/COSE Budget-Attestation envelope to prove bounded authority to spend, consume metered service units, or commit bounded resources. The mechanism is algorithm-agile; the initial cose-ml-dsa proof profile uses existing JOSE and COSE serializations for ML-DSA, with ML-DSA-65 as the baseline algorithm and ML-DSA-87 available as a high-assurance deployment policy option. A dedicated 4NN Delegated Authority Required status code remains an open design question for HTTP Working Group review; this revision does not depend on that status code and does not define payment semantics. This revision also defines a mandatory-to-implement preflight flow for large proof profiles so that GET and HEAD requests do not depend on request content, and so that requests with application representations do not need to multiplex the application body and the proof body in a single content stream. For implementation experience, this individual draft also includes the initial Budget authority profile. The HTTP authentication scheme, status-code semantics, Problem Details members, and field- carriage rules are intentionally separable from the COSE/CBOR Budget profile. If a Working Group chooses to progress the HTTP mechanism independently, the Budget authority profile can be moved to a companion profile document without changing the Delegation challenge semantics defined here. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-mcgraw-httpapi-agent-budget/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-mcgraw-httpapi-agent-budget-03.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-mcgraw-httpapi-agent-budget-03 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]