A brief and unromantic history of ActivityPub

Where is this mandated? In the AP Recommendation I see descriptions of some optional endpoints that state “If OAuth 2.0 bearer tokens […] are used” (conditional) and I see some informative references to OAuth specs, but I don’t see any mandate that limits C2S developers to OAuth 2.0. There’s a link to a “best practices” document (AKA, a nonnormative “primer”), but that’s not a mandate either.

2 Likes