* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)
* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)
on the proof side specifically, we're putting IAL2 verification in front of this <a href="https://pages.nist.gov/800-63-3-Implementation-Resources/63A/ial2remote/" rel="nofollow">https://pages.nist.gov/800-63-3-Implementation-Resources/63A...
pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf
Uh, not sure I agree with your terminology - one does not authorize who you are. You authenticate yourself, certain tokens authenticate your identity with varying levels of strength (e.g. within a corporate enclave, you may have elevated authorizations if you are authenticating from a corporate device).
Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.
thank you for the clarification - thankfully some much smarter people than I are working on the protocol aspects :)
when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".
I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so
Good point. Identity is not the same thing as authority. We're working on the authority piece at tenuo.ai (with a corresponding IETF protocol effort)
x401throaway · · focus · HN ↗
<a href="https://x401.proof.com/spec/latest/#abstract" rel="nofollow">https://x401.proof.com/spec/latest/#abstract
in a nutshell:
* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)
* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)
on the proof side specifically, we're putting IAL2 verification in front of this <a href="https://pages.nist.gov/800-63-3-Implementation-Resources/63A/ial2remote/" rel="nofollow">https://pages.nist.gov/800-63-3-Implementation-Resources/63A...
pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf
0xWTF · · focus · HN ↗
Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.
x401throaway · · focus · HN ↗
when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".
I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so
SgtBastard · · focus · HN ↗
Authorization is the process of determining if someone can do something.
That you’re conflating multiple distinct concerns doesn’t build confidence.
niyikiza · · focus · HN ↗