---
term: "HTTP Message Signatures"
category: "Agent identity (KYA)"
url: https://agenticopenfinance.com/glossary/http-message-signatures
source: AgenticOpenFinance glossary
---

# HTTP Message Signatures

> An IETF standard for signing selected parts of an HTTP request or response so the receiver can verify them.

HTTP Message Signatures, defined in RFC 9421, is an IETF standard for creating, encoding and verifying digital signatures or message authentication codes over selected components of an HTTP message, such as the method, path, headers and body digest. The receiver can verify both who signed the message and that the signed parts were not altered. Several agent identity schemes, including work in the IETF Web Bot Auth working group, build on it to let sites verify which operator sent a request.

Related terms: [Web Bot Auth](https://agenticopenfinance.com/glossary/web-bot-auth.md), [Know Your Agent (KYA)](https://agenticopenfinance.com/glossary/know-your-agent.md), [Trusted Agent Protocol](https://agenticopenfinance.com/glossary/trusted-agent-protocol.md), [DPoP](https://agenticopenfinance.com/glossary/dpop.md)
