@npub1hhkm...qk6s pointed UCAN out to me this morning, which is an interesting protocol for bearer token authotization. I can imagine this being useful for nostr, but I'm not sure exactly how yet. Maybe a better way to do relay authorization or social circle-type features?

GitHub
GitHub - ucan-wg/spec: User Controlled Authorization Network (UCAN) Specification
User Controlled Authorization Network (UCAN) Specification - ucan-wg/spec
Because the proof token is signed with the resource owner's private key, the service can easily validate that the proof is correct and hasn't been tampered with to grant unauthorized capabilities.
View quoted note →