9 comments
https://x401.proof.com/spec/latest/#abstract
in a nutshell:
* a website that wants to authorize who you are (say, to book a flight or sign a waiver for go kart rental)
* the endpoint returns 401 and defines in a header what info it needs about you (over 18? you're actually John Doe? etc.)
on the proof side specifically, we're putting IAL2 verification in front of this https://pages.nist.gov/800-63-3-Implementation-Resources/63A...
pretty cool stuff, its early days but its a strong way to ensure there's a human authorizing sensitive actions an agent is taking on your behalf
Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.
when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".
I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 3 days ago
- Can you forget how you feel about Meta?theverge.comThe Verge · 0 points · 9 days ago
- The Verge · 0 points · 5 days ago
- Can John Ternus find Apple’s next big thing?theverge.comThe Verge · 0 points · 10 days ago
- Hacker News · 73 points · 9 days ago
- The Verge · 0 points · about 5 hours ago