topic Registered
Verified 2026-09-19 · registry updated 2025-02-18

HTTP registry: PrivateToken

Registered value from the IANA HTTP registry.

Authentication registry values define how a client proves identity or possession of credentials to an origin or proxy. PrivateToken is registered in HTTP Authentication Schemes. Defining reference: RFC9577, Section 2.

httpregistryhttp-authschemesauthschemes

Identifier (http)

PrivateToken

Registered value from the IANA HTTP registry.

Use TLS, validate issuer/audience or challenge parameters, scope credentials to the correct hop, and design expiry, rotation, and replay handling explicitly.

This registry value is currently marked active by IANA. Follow the defining specification before sending, accepting, or proxying it.

IANA registry: http-authschemes/authschemes

Registry reference: RFC9577, Section 2

Permalink: https://merginit.com/reference/http/registry/http-authschemes/authschemes/privatetoken-28