Expand ↗
Page list (1268)

Macaroons

Birgisson, Politz, Erlingsson, Taly, Vrable & Lentczner’s (2014) lightweight authorisation tokens — HMAC-chained capability tokens supporting attenuation (the holder can derive strictly less-permissive sub-tokens) and third-party caveats (delegating verification of a condition to a separate service). The most-deployed modern descendant of SPKI/SDSI capability certificates, used in production at Google and elsewhere. A practical realisation of Capability Security in HTTP-API authorisation.

In this vault

Backlinks