Skip to content

Clarify §22.7 against Web Bot Auth “No Human Correlation” #6

Description

@aurel-fr

Location

§1.1.5 and §22.7.

Problem

§22.7 stores an agent_key_thumbprint beside a stable per-human continuity handle. Web Bot Auth says its signing key MUST NOT be tied to a specific human individual: §6.2.

The example does not say whether agent_key_thumbprint is the Web Bot Auth signing key. If it is, the example appears to conflict with that privacy requirement.

Required decision

Either:

  • state that this is a separate, origin-scoped delegation credential rather than the Web Bot Auth signing key;
  • rescope or remove the mapping; or
  • document why the composition is compatible with Web Bot Auth’s privacy requirements.

Cross-reference the delegation-semantics issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions