HTTP Message Signatures
An IETF standard for signing selected parts of an HTTP request or response so the receiver can verify them.
HTTP Message Signatures, defined in RFC 9421, is an IETF standard for creating, encoding and verifying digital signatures or message authentication codes over selected components of an HTTP message, such as the method, path, headers and body digest. The receiver can verify both who signed the message and that the signed parts were not altered. Several agent identity schemes, including work in the IETF Web Bot Auth working group, build on it to let sites verify which operator sent a request.
Agent Minute explains this term on 11 February 2027.
Related terms
Web Bot AuthIETF work on cryptographically authenticating automated clients, including agents, to websites.Know Your Agent (KYA)Checking which agent is acting, who operates it and whom it acts for, before letting it act.Trusted Agent ProtocolVisa's specification for signals that let merchants recognise trusted commerce agents and the consumer behind them.DPoPAn OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.