{
  "number": 8292,
  "title": "Voluntary Application Server Identification (VAPID) for Web Push",
  "authors": [
    "M. Thomson",
    "P. Beverloo"
  ],
  "published": "2017-11",
  "status": "Proposed Standard",
  "stream": "IETF",
  "area": "art",
  "working_group": "webpush",
  "pages": 14,
  "formats": [
    "TXT",
    "HTML"
  ],
  "abstract": "An application server can use the Voluntary Application Server Identification (VAPID) method described in this document to voluntarily identify itself to a push service. The \"vapid\" authentication scheme allows a client to include its identity in a signed token with requests that it makes. The signature can be used by the push service to attribute requests that are made by the same application server to a single entity. The identification information can allow the operator of a push service to contact the operator of the application server. The signature can be used to restrict the use of a push message subscription to a single application server.",
  "keywords": [
    "authentication",
    "restricted",
    "restriction",
    "signature"
  ],
  "draft": "draft-ietf-webpush-vapid-04",
  "doi": "10.17487/RFC8292",
  "urls": {
    "html": "https://rfc.dk/rfc8292/",
    "text": "https://rfc.dk/rfc8292.txt",
    "rfc_editor": "https://www.rfc-editor.org/rfc/rfc8292",
    "datatracker": "https://datatracker.ietf.org/doc/rfc8292/"
  },
  "text_modified": "2017-11-29T20:37:15.402469981Z"
}
