- From: <internet-drafts@ietf.org>
- Date: Sat, 04 Apr 2026 07:31:53 -0700
- To: <i-d-announce@ietf.org>
- Cc: ietf-http-wg@w3.org
Internet-Draft draft-hardt-httpbis-signature-key-03.txt is now available. It
is a work item of the HTTP (HTTPBIS) WG of the IETF.
Title: HTTP Signature-Key Header
Authors: Dick Hardt
Thibault Meunier
Name: draft-hardt-httpbis-signature-key-03.txt
Pages: 23
Dates: 2026-04-04
Abstract:
This document defines the Signature-Key HTTP header field for
distributing public keys used to verify HTTP Message Signatures as
defined in RFC 9421. Five initial key distribution schemes are
defined: pseudonymous inline keys (hwk), self-issued key delegation
via JWK Thumbprint JWTs (jkt-jwt), identified signers with JWKS URI
discovery (jwks_uri), JWT-based delegation (jwt), and X.509
certificate chains (x509). These schemes enable flexible trust
models ranging from privacy-preserving pseudonymous verification to
PKI-based identity chains and horizontally-scalable delegated
authentication.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-hardt-httpbis-signature-key-03.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-hardt-httpbis-signature-key-03
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
Received on Saturday, 4 April 2026 14:31:57 UTC