RFC 6896 · INFORMATIONAL · 2013

SCS: KoanLogic's Secure Cookie Sessions for HTTP

Overview

RFC 6896, “SCS: KoanLogic's Secure Cookie Sessions for HTTP”, is an Informational document published in March 2013 by S. Barbato, S. Dorigotti, T. Fossati. The canonical text is published by the RFC Editor.

Abstract

This memo defines a generic URI and HTTP-header-friendly envelope for carrying symmetrically encrypted, authenticated, and origin-timestamped tokens. It also describes one possible usage of such tokens via a simple protocol based on HTTP cookies.

Secure Cookie Session (SCS) use cases cover a wide spectrum of applications, ranging from distribution of authorized content via HTTP (e.g., with out-of-band signed URIs) to securing browser sessions with diskless embedded devices (e.g., Small Office, Home Office (SOHO) routers) or web servers with high availability or load- balancing requirements that may want to delegate the handling of the application state to clients instead of using shared storage or forced peering.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 6896 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2013

Who Is Online

In total there are 42 users online: 0 registered, 35 guests and 7 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Baiduspider Facebook Majestic Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354