* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)
* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)
on the proof side specifically, we're putting IAL2 verification in front of this <a href="https://pages.nist.gov/800-63-3-Implementation-Resources/63A/ial2remote/" rel="nofollow">https://pages.nist.gov/800-63-3-Implementation-Resources/63A...
pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf
Uh, not sure I agree with your terminology - one does not authorize who you are. You authenticate yourself, certain tokens authenticate your identity with varying levels of strength (e.g. within a corporate enclave, you may have elevated authorizations if you are authenticating from a corporate device).
Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.
Maybe related. I was always confused with the authorization header and 401 status code (unauthorized).
I've only ever seen authorization header containing credentials (i.e. authentication, who you are) instead of authorization (what you can do).
Also everyone returns 401 when unauthorized (i.e. can't do a thing), instead of 403 (forbidden, i.e. can't do the thing). When 401 should probably be "unauthenticated" (we don't know who you are, so we can't authorize you).
x401throaway · · focus · HN ↗
<a href="https://x401.proof.com/spec/latest/#abstract" rel="nofollow">https://x401.proof.com/spec/latest/#abstract
in a nutshell:
* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)
* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)
on the proof side specifically, we're putting IAL2 verification in front of this <a href="https://pages.nist.gov/800-63-3-Implementation-Resources/63A/ial2remote/" rel="nofollow">https://pages.nist.gov/800-63-3-Implementation-Resources/63A...
pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf
0xWTF · · focus · HN ↗
Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.
Knufferlbert · · focus · HN ↗
I've only ever seen authorization header containing credentials (i.e. authentication, who you are) instead of authorization (what you can do).
Also everyone returns 401 when unauthorized (i.e. can't do a thing), instead of 403 (forbidden, i.e. can't do the thing). When 401 should probably be "unauthenticated" (we don't know who you are, so we can't authorize you).
Always messes with my head a bit.