Skip to Content
SpecificationsOverview

Specifications

AAuth is defined by a family of layered specifications. Each layer builds on the one below it, providing primitives that higher layers use.

Layers

LayerSpecStatusPrimitives
4bR3 — Rich Resource RequestsExploratoryVocabulary-based authorization, content-addressed audit
4aMissionExploratoryScoped authorization contexts, centralized audit
3AAuth ProtocolInternet-DraftToken issuance, federation, deferred authorization
2AAuth HeadersInternet-DraftRequirement signaling, error reporting
1Signature-KeyInternet-DraftKey conveyance, signature bootstrapping

Reading the Specs

The Internet-Drafts are published on the IETF Datatracker. The exploratory specs are available as editor’s copies on GitHub. Each spec page on this site provides a summary of what the layer does and links to the authoritative source.

For a non-normative introduction to the concepts, start with the Explainer.