Flow 1
WIT + WPT on an HTTP call
- 1
Caller sends Workload-Identity-Token and Authorization: WPT <jwt>.
- 2
Callee validates WIT (trust anchors, exp, cnf).
- 3
Callee checks WPT typ, alg match, signature with WIT's cnf key, wth matches this WIT, aud/time bindings.
- 4
Authorization policy uses workload identity from WIT plus any Txn-Token context — not a sibling Bearer token.