Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -141,7 +141,7 @@ sequenceDiagram
Agent->>PS: POST /person (signed, resource)
PS-->>Agent: person_token
Agent->>Resource: GET /data (signed, person_token)
Resource-->>Agent: 401 + requirement=auth-token; resource_token
Resource-->>Agent: 401 + requirement=auth-token, resource_token
Agent->>PS: POST /token (signed, resource_token + presented_token)
PS->>User: Consent prompt (scope, justification)
User-->>PS: Grant consent
Expand Down
6 changes: 3 additions & 3 deletions docs/getting-started.md
Original file line number Diff line number Diff line change
Expand Up @@ -173,15 +173,15 @@ sequenceDiagram
Resource->>Resource: Verify agent token and key proof
Resource-->>Agent: 401 + requirement=person-token

Agent->>PS: POST /person (signed; resource=https://resource.example)
Agent->>PS: POST /person (signed, resource=https://resource.example)
PS->>PS: Validate agent token, mission/context and person selection
PS-->>Agent: person_token (aa-person+jwt)

Agent->>Resource: GET /data (Signature-Key: sig=jwt, person token)
Resource->>Resource: Verify person token, copy ps/sub and set presented_jti
Resource-->>Agent: 401 + requirement=auth-token; resource-token=...
Resource-->>Agent: 401 + requirement=auth-token, resource-token=...

Agent->>PS: POST /token (signed; resource_token + presented_token)
Agent->>PS: POST /token (signed, resource_token + presented_token)
PS->>PS: Verify resource token and the named presented token
PS->>User: Consent prompt (scope, justification)
User-->>PS: Grant consent
Expand Down
4 changes: 2 additions & 2 deletions docs/workflows/bootstrap-enrollment.md
Original file line number Diff line number Diff line change
Expand Up @@ -213,8 +213,8 @@ sequenceDiagram
participant AP as Agent Provider
Note over Agent: Token nearing expiry
Agent->>Agent: Generate ephemeral Ed25519 key
Agent->>Agent: Build naming JWT (jkt-s256+jwt, signed by durable key,<br/>durable jwk in header, iss=urn:jkt:sha-256:&lt;thumbprint&gt;,<br/>ephemeral key as cnf.jwk)
Agent->>AP: POST /refresh {} (signed with ephemeral key,<br/>Signature-Key: sig=jkt-jwt;jwt="&lt;naming-jwt&gt;")
Agent->>Agent: Build naming JWT (jkt-s256+jwt, signed by durable key,<br/>durable jwk in header, iss=urn:jkt:sha-256:#lt;thumbprint#gt;,<br/>ephemeral key as cnf.jwk)
Agent->>AP: POST /refresh {} (signed with ephemeral key,<br/>Signature-Key: sig=jkt-jwt#59;jwt="#lt;naming-jwt#gt;")
AP->>AP: Self-anchor — thumbprint(header jwk) == iss, verify naming JWT signature
AP->>AP: Look up enrolment by the durable key thumbprint (bind to record)
AP->>AP: Verify HTTP signature against ephemeral cnf.jwk
Expand Down
2 changes: 1 addition & 1 deletion docs/workflows/federated-access.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ sequenceDiagram
Agent->>Resource: GET /data (signed, person token)
Resource-->>Agent: 401 + resource token (aud=AS URL)
Agent->>PS: POST /token (resource_token, presented_token)
PS->>AS: POST /token (signed; resource_token, agent_token, presented_token)
PS->>AS: POST /token (signed, resource_token, agent_token, presented_token)
AS-->>PS: auth token (iss=AS)
PS-->>Agent: auth token
Agent->>Resource: GET /data (signed, auth token)
Expand Down
2 changes: 1 addition & 1 deletion docs/workflows/ps-asserted-access.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ sequenceDiagram
Agent->>PS: POST /person (signed, resource in body)
PS-->>Agent: 200 + person token (aa-person+jwt)
Agent->>Resource: GET /data (signed, sig=jwt with person token)
Resource-->>Agent: 401 requirement=auth-token + resource token (aud=PS; presented_jti)
Resource-->>Agent: 401 requirement=auth-token + resource token (aud=PS, presented_jti)
Agent->>PS: POST /token (signed, resource_token + presented_token)
PS-->>Agent: 200 + auth token (aa-auth+jwt)
Agent->>Resource: GET /data (signed, sig=jwt with auth token)
Expand Down
2 changes: 1 addition & 1 deletion docs/workflows/resource-managed-access.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ sequenceDiagram
participant User
Note over Agent: Setup complete: self-issued or AP-enrolled agent JWT
Agent->>Resource: GET /data (jwt + HTTP proof)
Resource-->>Agent: 202 + Location + requirement=interaction; url; code
Resource-->>Agent: 202 + Location + requirement=interaction, url, code
Note over Agent: Start signed polling immediately
User->>Resource: Completes interaction at resource's page
Agent->>Resource: GET /pending/<id> (poll)
Expand Down
4 changes: 2 additions & 2 deletions docs/workflows/wallet-protocol.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ sequenceDiagram
Agent->>PS: Signed pending GET
PS-->>Agent: AS-issued auth_token
Agent->>Wallet: Review with auth_token
Wallet-->>Agent: 200; charge with same scope is rejected
Wallet-->>Agent: 200, charge with same scope is rejected
```

## Chaining an AS-Issued Grant
Expand Down Expand Up @@ -96,7 +96,7 @@ sequenceDiagram
Concierge->>PS: resource_token, presented_token, upstream_token
PS->>AS: Signed federation, agent_token (Concierge), presented_token, upstream_token
AS->>AS: Validate upstream audience and PS, presented token, scope
AS-->>PS: Downstream auth_token (ps, sub; no agent or act claim)
AS-->>PS: Downstream auth_token (ps, sub, no agent or act claim)
PS-->>Concierge: Downstream auth_token
Concierge->>Wallet: Retry with downstream auth_token
Wallet-->>Concierge: 200
Expand Down
2 changes: 1 addition & 1 deletion samples/Concierge/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ sequenceDiagram
C->>Cal: GET /events (signed, person token)
Cal-->>C: 401 + resource_token
C->>PS: exchange resource_token + presented_token + upstream_token
PS-->>C: downstream auth token (ps + sub name the person; no agent or act)
PS-->>C: downstream auth token (ps + sub name the person, no agent or act)
C->>Cal: GET /events (signed, downstream auth token)
Cal-->>C: 200 OK
C-->>A: 200 OK (combined chain result)
Expand Down
Loading