Flow 1
Issue and present a WIT
- 1
Identity server mints wit+jwt with sub, cnf.jwk, exp on the order of hours.
- 2
Workload presents Workload-Identity-Token plus a WPT (or HTTP signature) proving cnf.
- 3
Recipient validates against configured trust anchors for the trust domain in sub, then the proof.
- 4
On WIT validation failure, prefer HTTP 400 with problem details, not 401 Bearer — 401's WWW-Authenticate/Authorization pairing is not how WIT works.