upvote
Maybe related. I was always confused with the authorization header and 401 status code (unauthorized).

I've only ever seen authorization header containing credentials (i.e. authentication, who you are) instead of authorization (what you can do).

Also everyone returns 401 when unauthorized (i.e. can't do a thing), instead of 403 (forbidden, i.e. can't do the thing). When 401 should probably be "unauthenticated" (we don't know who you are, so we can't authorize you).

Always messes with my head a bit.

reply
thank you for the clarification - thankfully some much smarter people than I are working on the protocol aspects :)

when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".

I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so

reply