[Web-bot-auth] Re: Interest in the human-principal layer above bot authentication

Dick Hardt <dick.hardt@gmail.com> Mon, 06 July 2026 13:00 UTC

Return-Path: <dick.hardt@gmail.com>
X-Original-To: web-bot-auth@mail2.ietf.org
Delivered-To: web-bot-auth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id AB64911017BDB for <web-bot-auth@mail2.ietf.org>; Mon, 6 Jul 2026 06:00:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783342853; bh=l9RWaOETLPsgWVyR6AUVP79ECSnH1IDeZEK0p8CkBJw=; h=References:In-Reply-To:Reply-To:From:Date:Subject:To:Cc; b=xDLUiYezmR68naciV6SD85f9r8GyjjUiieiUnSWxg5+dMgmpAUKPtKYf5TvsCFr5R QDPBQzQNQVEfundJ5+u69023kXqn6IT5uOsTr44cRSu5/k2AtQzL5VOppLvjM/wfkk nV6kKh4GQl9wWaYThxa986gM3Yup8y3+hbwvSCNg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1EodWxLV2u89 for <web-bot-auth@mail2.ietf.org>; Mon, 6 Jul 2026 06:00:52 -0700 (PDT)
Received: from mail-ot1-x32d.google.com (mail-ot1-x32d.google.com [IPv6:2607:f8b0:4864:20::32d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 36A6C110159E7 for <web-bot-auth@ietf.org>; Mon, 6 Jul 2026 05:59:21 -0700 (PDT)
Received: by mail-ot1-x32d.google.com with SMTP id 46e09a7af769-7e9ecd7216cso1271222a34.3 for <web-bot-auth@ietf.org>; Mon, 06 Jul 2026 05:59:21 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783342760; cv=none; d=google.com; s=arc-20260327; b=k9YPZSwimvt0qVjCJgoygvVVdHHyspXOeGNeDZBKmqyd/e6Uy7bNE69pG04FUgEs2T gis/H7Q1npzrx7EDp1IhTz478fOw8CkqUvjhznqdEkQDRj93Ctega55E6BZuxLo0YuKe 92xIWd76J5ykl9cZs5w7cHcVZ6+KFSQt7AcbzLudYNnKaegxULdt/+Xkbl+4gSxv+T4q QwSM0RmgFPf1rnP1zHjq6EWCzyVSdtmj3V5SmmDl1ss3Bnc/R/HeNekykTGv1aOISL4c PwPSfbhUPvwdt8XXO43NF9UR3wlMgkjlA+qPprIsk+jfnvxoDy+SGoeMRkwDA1/TLAle WtkA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:reply-to:in-reply-to:references :mime-version:dkim-signature; bh=m0rrIxJomQab08FC44K8vORoxZvvf4n2Vn2Wim+HeOQ=; fh=9PSz3SbO0hBZMB6C+Y/C425ENQ1R1CKpDtqXg9YBnwg=; b=DMdMvZZQwHlXYFl/oEMTWR1frREm3z/+416O4sDaoBni6TmCmS1FKrkmH+KKIOnTh0 3SU1DXoNjJ1gck+HDlrOVOnyJQlIIZ5X30j760B5yv1jbZKdiaceItXUlR0apln5AN5x 7Xid+T47KZx/73PWfRj32CzjmeBybdGKQJeYREg+03GbGnDnu9tg3HASEhBt3/FxZ6EU LUw/ddB0ScqO076Cup0IKNi/xsKBegyUHc9O1RLO2OlzUd5duYd5wqR9u5Kakm5SdcIB 1Omt6GcckQeNRaGwJ+m7ZBORLUwH9r+na1gJhsW34vTLLBaOdyRV6he69QnvkQMh7ajj z2TQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783342760; x=1783947560; darn=ietf.org; h=cc:to:subject:message-id:date:from:reply-to:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=m0rrIxJomQab08FC44K8vORoxZvvf4n2Vn2Wim+HeOQ=; b=a/zxf3Sa3xnbrmxtoqSM/t54fsf435M/SqBsVPgtiF+hWZC88IxEIu2hKTAHAELygz 7kLaSZ65NOfJ3aOQEOsc6wUGzkJlKgi1ijsOLzZ6G4ZnB9u9ZSY0UIjt9TRoJL7Gb+k0 d8ZJd/1mdfxEPtMX3S9pm/sEcfdqQxgfscfEp6+JiNnSj5B5+SuDXAVbQqb/sIR4brYn XoXkXWMXRnBWNfYI/1+hCjgsu5R5O1GmtBT2EdiNpx6M4z0VHNavWxRTgdkRiGGELZMB XUK8Xir6Zl0KMSiXuupFknuRW+PBHosUyX9lR0KdArNLdt8ihgZ8x6uKGtstCf5Z2INP B8/A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783342760; x=1783947560; h=cc:to:subject:message-id:date:from:reply-to:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=m0rrIxJomQab08FC44K8vORoxZvvf4n2Vn2Wim+HeOQ=; b=V7H0U6UyRG/tdZ5tj1QbGv3CROqL6p6XGEhTaNBorkoQ14dm+zP8CESZs3+PopUR7m iRJ8/p9sOgxA5QpC7ttMIP5HIz+yLpviz9qoBn0KMVNwK0FuKodf71AcfwQiiDNhbFL8 YWCf7fMXWZMDLVFCg3rGzTEWbfZe5z2v/e7LitF1lPuT4ngZV52aK+qjSih6wM5BTSKQ 9mBK6zIh+IiKIrUmDmMEWbltMewQ0Zn/Y86Bu4/r7TGu1F8l3rXd0A9/nhd1DEm935sN KL1UZ4aj15uCwas05hI0z2zHtMJo7xL6aXNv+CD/45ffdwoayEUzID9dloQ2Q2Kds1mf QaVQ==
X-Forwarded-Encrypted: i=1; AFNElJ/uvKapM+CWPQFhEgFmUKssGK2+HtRRSMJTH/IqD6cNrn8Iz7V5cyuOLEygqTE4BXPbBkI/n7X07V6i/w0=@ietf.org
X-Gm-Message-State: AOJu0YwA8OtxWjqc1M4IYDZUxyey6N32qos4DmyBMw6Mi0ylS5simIyX A5P4BQUHeJtk1DefQAmiN59QqQIJIl596Pq4rrgtsFDwyFp3Q6gdJCmVu4qDa1DSwxadD1KNx7i weuP97igwyTcwqlgcLbEI8h7QFctv5CP19xGB
X-Gm-Gg: AfdE7cm/+g65of/7QO0RhBdiqs1lSpNzO62lWKhNO/MHxtOlsWE1UuEHb9B/uRa+cjS y/8jZX3dAjRYuaEs3DYup92XFTeUa0efYMoldFXgxNtkJEO5fdduk8ROZ+K8/19Yi3HUaCI00Zu 5IsfPYv3XehXh3LzlVM/9xsitmIRDiO9kWCU8zTQ7qcOMyAodP0Rj7MdK/q/Si2fCjR/I8MIOtO cP0FQJjvKnZPR2DHPe1ZFDcsD3Uk74aucy49nhFf+v14LUwrDvRdQScqW0wP3rwQB8/imvPkzCe pC6Lz9EKHT0ufrMbB0+5pgv8hJoE3g==
X-Received: by 2002:a05:6830:3c8b:b0:7e9:dc88:f10a with SMTP id 46e09a7af769-7ebb2321593mr130583a34.18.1783342760389; Mon, 06 Jul 2026 05:59:20 -0700 (PDT)
MIME-Version: 1.0
References: <9NfVj76IAWXePMt_ecu6nZev0qj-LLusr-b7YWkDU8jgH_Olfoo1XIf9eYpv0GdU0Xu7WgT_bGNO40Tl1mhMeSL1MqqyoRzdi_j2Vtw8VOw=@truealter.com> <CAK08nYaLoTFPdTkS02zn=gQVV1iusAO498T-LHBG0nhXpt2n5g@mail.gmail.com> <DBBPR01MB1065135176528738FB9EC978495F12@DBBPR01MB10651.eurprd01.prod.exchangelabs.com>
In-Reply-To: <DBBPR01MB1065135176528738FB9EC978495F12@DBBPR01MB10651.eurprd01.prod.exchangelabs.com>
From: Dick Hardt <dick.hardt@gmail.com>
Date: Mon, 06 Jul 2026 13:58:44 +0100
X-Gm-Features: AVVi8CffPzyCM_GMuSiaK00etLw03BBNh7ZfjE_ij23dBfpbcAT3bD5Worw-8m4
Message-ID: <CAD9ie-uov_0T02H_r762Vyg5VJDZQdMk3F=DYw1dmVQB=0_Wmw@mail.gmail.com>
To: Srecko Jovancevic <Srecko.Jovancevic@skgo.org>
Content-Type: multipart/alternative; boundary="000000000000beef2d0655f0d76a"
Message-ID-Hash: SFJO5WPLY35OEZLQXUMNBO5XQRQTT4L3
X-Message-ID-Hash: SFJO5WPLY35OEZLQXUMNBO5XQRQTT4L3
X-MailFrom: dick.hardt@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Songbo Bu <bluedognull@gmail.com>, "web-bot-auth@ietf.org" <web-bot-auth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: Dick.Hardt@gmail.com
Subject: [Web-bot-auth] Re: Interest in the human-principal layer above bot authentication
List-Id: Authentication of non-human users to human-oriented Web sites <web-bot-auth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/web-bot-auth/iK_063QDIh0X96rKRQ_We25YBKs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/web-bot-auth>
List-Help: <mailto:web-bot-auth-request@ietf.org?subject=help>
List-Owner: <mailto:web-bot-auth-owner@ietf.org>
List-Post: <mailto:web-bot-auth@ietf.org>
List-Subscribe: <mailto:web-bot-auth-join@ietf.org>
List-Unsubscribe: <mailto:web-bot-auth-leave@ietf.org>

AAuth might be what you are looking for.

It builds on a similar http message signing primitive for agent identity as
WBA, and lets a resource request either identity and/or authorization,
using the same patterns as OpenID Connect and OAuth. We had an AAuth night
in SF last week during tha AI Engineering World's Fair and 160 people
attended and a number of independent vendors showed live demos of AAuth in
action.

https://datatracker.ietf.org/doc/draft-hardt-oauth-aauth-protocol/

https://aauth.dev

I have scheduled a side meeting for Thursday afternoon in Vienna.

/Dick



On Mon, Jul 6, 2026 at 9:45 AM Srecko Jovancevic <Srecko.Jovancevic@skgo.org>
wrote:

> Blake, Songbo, all,
>
> Welcome, Blake. I'm following this mostly as an observer, so take
> this as observation rather than a position -- and I land where
> Songbo did: if a human-principal assurance is wanted, it belongs
> as a separate verifier-facing claim carried beside the request,
> never in the bot signing key.
>
> It may help the scope question to lay out where the existing
> mechanisms actually sit relative to a human principal, because the
> pattern is consistent -- almost none carry one, and mostly by
> design:
>
>   - Web Bot Auth / httpsig authenticates the automated client's
>     key, and Section 6.2 deliberately forbids tying that key to a
>     person. Human principal: excluded by design.
>
>   - SAIP identifies the agent at vendor/type/instance level; its
>     identity is the automation, not a human (no human
>     correlation). Same deliberate exclusion.
>
>   - The anonymous approaches -- Rescorla/Barnes ABA, and PACT --
>     remove identity entirely; a named human principal is the
>     opposite of what they provide.
>
>   - VDAC (my own) binds an agent and a site in a mutual contract.
>     That is accountable, but the parties are the agent and the
>     site, not a consent-bound human standing behind a single
>     request -- so it's adjacent, not this layer either.
>
>   - Songbo's verifier matrix is the one framework here with a slot
>     for it: a separate row (his human/org authority claim),
>     carried beside the request, verified under the origin's own
>     rules, failing independently of bot-key verification.
>
> So to your scope question directly: the human-principal layer
> looks out of scope for the signing key and for this group's core
> deliverable -- every agent-auth mechanism here keeps the human out
> of the key on purpose, and the anonymous ones remove identity
> altogether -- but it's a legitimate adjacent layer that a separate
> effort or a profile could carry, and it already has a clean shape
> in Songbo's row model. Wherever it lands, it would want to inherit
> this group's base posture: optional and default-off, so it never
> becomes a de facto human-identification gate.
>
> One distinction that may be worth making explicit, reading the
> drafts from the side: "human principal" is doing double duty.
> draft-morrison-consent-settlement carries the human as the data
> subject an attribute is about (consent plus settlement); the
> authority behind the agent -- the party on whose behalf it acts --
> is a different role, and as far as I can see none of the drafts,
> including the bilateral two-entity case in
> draft-morrison-identity-accord, squarely carries that one. If that
> reading is right, the scope question sharpens to: is there room for
> that authority claim, as an optional row beside the request?
>
> Best regards,
> Srecko
> ------------------------------
> *From:* Songbo Bu <bluedognull@gmail.com>
> *Sent:* Monday, July 6, 2026 8:33 AM
> *To:* web-bot-auth@ietf.org <web-bot-auth@ietf.org>
> *Subject:* [Web-bot-auth] Re: Interest in the human-principal layer above
> bot authentication
>
> Hi Blake, all,
>
> I think the separation you describe is the right one: the Web Bot Auth
> signing key should remain the automated-client key, not a human key.
> If a deployment needs a human-principal assertion, I would model it as
> a separate verifier-facing claim carried alongside the request, or
> referenced from it, rather than as a change to the bot signing key.
>
> One way to keep the scope clean is to state it as a separate row:
>
> - Claim: a named, consented, or otherwise accountable human principal
> stands behind, approved, or is associated with this request under a
> stated grant or consent rule.
> - Carrier: a consent receipt, authorization receipt, signed grant, or
> external reference; not the Web Bot Auth signing key itself.
> - Verifier and rule: the origin or relying party verifies the
> human-principal artifact under its own issuer, key, and trust rules,
> separately from bot-key verification.
> - Binding and freshness: the human-principal artifact is bound to the
> request, origin, purpose, scope, time window, and, where applicable, a
> request or action digest.
> - Failure behavior: bot authentication can still succeed while the
> human-principal row fails; the application then treats the request as
> lacking that optional human-principal assurance.
>
> That keeps Web Bot Auth's base property intact while leaving room for
> profiles or companion work to define voluntary human-principal
> assertions. It also avoids implying that every bot request needs a
> human behind it, which would be the wrong default.
>
> I have been working on a protocol-neutral verifier-matrix draft for
> exactly this kind of separation:
>
> https://datatracker.ietf.org/doc/draft-bu-agentproto-security-principal-binding/
>
> The draft is not Web Bot Auth-specific, but its row model may be
> useful if this thread continues.
>
> Best,
> Songbo
>
>
> On Mon, 06 Jul 2026 01:55:18 +0000, Blake
> <blake=40truealter.com@dmarc.ietf.org> wrote:
> > Hello,
> >
> > I have been following the working group's drafts and wanted to introduce
> > myself and where my own work sits, ahead of 126.
> >
> > My name is Blake Morrison and I have been building agent-identity
> > infrastructure. The part I keep running into is the layer your charter
> > sets aside - the verified human principal behind an agent.
> >
> > Web Bot Auth proves an automated client controls its key, and Section
> > 6.2 is clear that the signing key must not be tied to a person. That
> > seems right to me.
> >
> > My question is whether there is room alongside that for an optional and
> > consent-bound way for a verified human to voluntarily stand behind an
> > agent's request, for the cases where an origin wants more than "this is
> > a well-behaved bot". I am not proposing to put any of that into the key
> > or the signature; I am asking whether the group sees the human-principal
> > layer as in scope, deliberately out of scope, or something a separate
> > effort should carry.
> >
> > The most relevant of my submitted drafts is
> > draft-morrison-consent-settlement, which defines a scoped, revocable
> > consent grant the subject issues for reads of identity attributes. I
> > raise it only as background, not as a proposal here.
> > https://datatracker.ietf.org/doc/draft-morrison-consent-settlement/
> >
> > I am not asking for adoption or for agenda time; I would value the
> > group's view on the scope question, and pointers to anything in this
> > space I have missed. I am following 126 remotely from Australia and
> > would be glad to talk it through on the list or a call.
> >
> > Thank you,
> >
> > Blake Morrison
> > Alter Meridian Pty Ltd
> > blake@truealter.com
> >
> > _______________________________________________
> > Web-bot-auth mailing list -- web-bot-auth@ietf.org
> > To unsubscribe send an email to web-bot-auth-leave@ietf.org
>
> _______________________________________________
> Web-bot-auth mailing list -- web-bot-auth@ietf.org
> To unsubscribe send an email to web-bot-auth-leave@ietf.org
> _______________________________________________
> Web-bot-auth mailing list -- web-bot-auth@ietf.org
> To unsubscribe send an email to web-bot-auth-leave@ietf.org
>