draft chu oauth subject key binding 00 OAuth Subject Signing Key Binding for Resource Servers
Verifying a subject's signature requires a trusted key relation. That relation does not independently establish the authority of the signed instruction or settle the application semantics the draft leaves open.
Verifying a subject's signature requires a trusted key relation. That relation does not independently establish the authority of the signed instruction or settle the application semantics the draft leaves open.
What the source establishes
An individual OAuth draft proposes conveying subject signing keys to resource servers through access tokens or introspection. The binding is scoped to the subject, server audience and token validity; enrollment and application level evidence semantics are expressly outside its scope.
Moona assessment and evidence limits
Verifying a subject's signature requires a trusted key relation. That relation does not independently establish the authority of the signed instruction or settle the application semantics the draft leaves open.
Verification scope
Moona reviewed the retained source on 29 September 2026. Source acquisition and review establish provenance for this account; they do not reproduce an experiment, validate a vendor deployment or authorize an action.
Sources
This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.
