RFC 7486 · EXPERIMENTAL · 2015

HTTP Origin-Bound Authentication

Overview

RFC 7486, “HTTP Origin-Bound Authentication”, is an Experimental document published in March 2015 by S. Farrell, P. Hoffman, M. Thomas. The canonical text is published by the RFC Editor.

Abstract

HTTP Origin-Bound Authentication (HOBA) is a digital-signature-based design for an HTTP authentication method. The design can also be used in JavaScript-based authentication embedded in HTML. HOBA is an alternative to HTTP authentication schemes that require passwords and therefore avoids all problems related to passwords, such as leakage of server-side password databases.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 7486 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2015

Who Is Online

In total there are 69 users online: 0 registered, 61 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Majestic Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372