As the proposer of this work, I’m in favor of adoption. The problem space is 
well defined and this solution composes two existing technologies in a way that 
fits both very cleanly. This work takes learnings from DPoP and OAuth mTLS as 
well as learnings from a few years of HTTPSig deployments in different spaces.

People in the wild are already applying HTTPSig to OAuth-protected calls in 
proprietary ways today, and a simple standard way to attach keys to OAuth 
tokens and clients would be a useful artifact in the wider ecosystem.

And to reiterate what I said on the call: this should not be seen as 
deprecation of DPoP or mTLS any more than they were seen as deprecations of 
each other (which is to say, they weren’t).

— Justin

On Sep 21, 2026, at 3:16 PM, Rifaat Shekh-Yusef <[email protected]> wrote:

All,

This is an official call for adoption for the OAuth Proof of Possession Tokens 
with HTTP Message Signatures draft:
https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html

Please, reply on the mailing list, on whether you support or oppose the 
adoption of this draft as a WG document by October 5th.

Regards,
 Rifaat & Hannes
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to