logoalt Hacker News

x401throaway • today at 5:44 PM • 1 reply • view on HN

I work at Proof, and we're working on x401 as a means for agentic authorization

https://x401.proof.com/spec/latest/#abstract

in a nutshell:

* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)

* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)

on the proof side specifically, we're putting IAL2 verification in front of this https://pages.nist.gov/800-63-3-Implementation-Resources/63A...

pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf


Replies

0xWTF • today at 6:46 PM

Uh, not sure I agree with your terminology - one does not authorize who you are. You authenticate yourself, certain tokens authenticate your identity with varying levels of strength (e.g. within a corporate enclave, you may have elevated authorizations if you are authenticating from a corporate device).

Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.

➕ show 2 replies