RFC 9421 HTTP signatures in 2026

For anyone wanting to test an RFC 9421 implementation, I set up a small bot that tell you if it’s working.

If you send a DM(*) to @echobot@bots.grilledcheese.social, it will write back telling you if your message was transport-signed using the HTTP draft (almost everyone) or RFC 9421. As a bonus, it will also tell you if your post was signed via FEP-8b32 assertion proof.

The server is attaching the “Accept-signature” header to all inbox replies, too, to advertise RFC signature support… though so far that has enticed zero servers into trying it.

(*) sometimes called “private mention”: any message with the “directMessage” flag or targeted only at mentioned actors

2 Likes