Flow 1
Sign a request
- 1
Choose components (minimum method, authority, path, key header).
- 2
Build Signature-Input with created and a nonce or keyid as required by the profile.
- 3
Sign the signature base; send Signature plus key discovery (Signature-Key or WIT).
- 4
Verifier rebuilds the base, fetches the key, checks alg, created window, and signature.