I support adoption. HTTP Message Signatures are already being combined with OAuth-protected requests, and a working-group-defined profile for key assignment and token binding would be preferable to divergent implementation-specific approaches.
Adoption should not imply that every current design choice is settled. In particular, I think the working group should clarify when this mechanism is preferable to DPoP or mTLS, resolve whether the pub/htsk approach is necessary versus alignment with JWK-based key representation, and define a sufficiently constrained verification profile to avoid unnecessary interoperability differences. Regards, Arjun Garg On Mon, 21 Sep 2026 15:16:49 -0400, Rifaat Shekh-Yusef < [email protected]> wrote: All, This is an official call for adoption for the *OAuth Proof of Possession Tokens with HTTP Message Signatures *draft: https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html Please, reply on the mailing list, on whether you support or oppose the adoption of this draft as a WG document by *October 5th*. Regards, Rifaat & Hannes
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
