a Secarta project ...

HTTPsec Authentication Protocol


Preamble

4.8. token

In an initialization response, the token directive is is an opaque reference to the newly initialized shared-secret arrangement. Its value is chosen by the responder, and MUST be unique within the responder's record of valid tokens. It's value MUST NOT contain whitespace, but its length or other characteristics are not otherwise constrained.

In a continuation Request the token directive is employed by the requester as a reference to a previously initialized shared-secret arrangement. From the perspective of both the request's requester and its responder, the referenced arrangement implies the MAC keys to create or validate mac directives, and implies the cipher keys for message body ciphering or deciphering.