As the proposer of this work, I’m in favor of adoption. The problem space is well defined and this solution composes two existing technologies in a way that fits both very cleanly. This work takes learnings from DPoP and OAuth mTLS as well as learnings from a few years of HTTPSig deployments in different spaces.
People in the wild are already applying HTTPSig to OAuth-protected calls in proprietary ways today, and a simple standard way to attach keys to OAuth tokens and clients would be a useful artifact in the wider ecosystem. And to reiterate what I said on the call: this should not be seen as deprecation of DPoP or mTLS any more than they were seen as deprecations of each other (which is to say, they weren’t). — Justin On Sep 21, 2026, at 3:16 PM, Rifaat Shekh-Yusef <[email protected]> wrote: All, This is an official call for adoption for the OAuth Proof of Possession Tokens with HTTP Message Signatures draft: https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html Please, reply on the mailing list, on whether you support or oppose the adoption of this draft as a WG document by October 5th. Regards, Rifaat & Hannes _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
