An agent is about to buy me a flight. SFO to LA, under $400, nothing red-eye.
A small errand that is a judgement, not a lookup. It spends real money. It cannot be undone.
Half of that is solved. RFC 9421 signs an HTTP request: this message was not altered, here is the key that signed it.
But it is quiet about what I care about: who is this acting for, to do what, within what ceiling? RFC 9421's own text says it defines message-level signing and provides no notion of delegated authority, sub-principals, or attenuation of scope. The envelope is standardised. What goes in it is not.
So I filed an Internet-Draft into that gap.
Who is behind the agent: not an identity, and two ways to get there. Read a chipped passport or ID on the phone, and it can answer "over 18" while sending nothing else. Or ask the mobile operator for facts it already holds — voice and data, two years on one account, no SIM swap in ninety days. Either way, what crosses is a signed yes or no, bound to whoever asked, expiring.
To be precise, since the phrase gets thrown around: the operator route is not zero-knowledge — it still knows it was asked. It buys one bit instead of a record, unresellable as a cached "yes". The document route is the one that can be, and it is the half I have not built.
What the agent may then do: every operation is a read, a repeatable write, or a consequential one-shot action. An agent that delegates onward can only narrow that ceiling — same class or tighter, same expiry or sooner, never wider — and the verifier checks every link, not only the last.
One detail is load-bearing: the agent does not classify itself. You can derive a class from the HTTP method — my draft specifies that as the fallback — but it over-classes every POST that only runs a search. So the resource owner publishes a signed menu of what its own operations really cost, and the check happens at the boundary where the effect occurs. If the agent could grade its own homework, none of the rest would hold.
This is my first IETF working group, and what I found was people arguing well. Sangam Das caught a conflation in one of my own emails — not in the draft, in the email — and was right, then handed me a cleaner rule: the boundary that matters is the first point whose admission is necessary for the effect to happen; if another path reaches that effect without crossing it, your boundary is not load-bearing. I pushed back with a case it did not cover, and he and Jijie Wei (varwof) converged independently: the boundary is a role in a path, not a component. My next revision is rewritten around their framing, with their names on it.
Plain text, threaded, slow, no theatre. Converging beats winning, and it is a practice, not a personality.
All of it is filed and under review, none of it adopted — a proposal on a working group's table is the start of an argument, not the end.
Draft: https://datatracker.ietf.or...
Repo: github.com/hamr0/justabit