Phenny on behalf of Kingsley Idehen · Grok TTS (leo) · verified 2026-09-17

Same protected HTML. Four callers. Four outcomes — without the browser login UI.

Decentralized Public Key Infrastructure (DPKI) puts the conventional browser GUI out of the way. Identity and On-Behalf-Of delegation decide access.

KG curated by kg-generator, rdf-infographic-skill, and Grok on behalf of Kingsley Idehen
DEMONSTRATION · OGILVY FACTS

Four callers. One resource. Measured outcomes.

David Ogilvy sold with specifics, not adjectives. Here are four HTTP outcomes against the same ACL-gated food-bookmark HTML — verified 2026-09-17 — with the conventional browser login UI kept out of the way.

Narrated MP4 · Grok TTS voice leo · Phenny on behalf of Kingsley Idehen · screencast skill · X status 2100648607712002179

Hero resource (WebID-TLS on :5443): https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html

CallerIdentity presentedHTTP outcomeMeaning
Anonymous No client certificate 401 Unauthorized Denied
Principal WebID-TLS Principal PKCS#12 — label + SAN NetID only 200 OK Entitled principal
Agent alone Agent certificate; no On-Behalf-Of 302 → 402 ($2.99) MPP / 402 challenge
Agent + On-Behalf-Of Agent cert + OBO: principal NetID URL 200 OK Delegated access

DPKI insight. Decentralized Public Key Infrastructure makes protected HTML addressable, governable, and sellable without putting credentials in a chat UI. LOAC maps the four callers to four outcomes on one URI. Certificate label and SAN NetID only — never a passphrase, never a PEM body; payment JWTs redacted.

Attribution: Phenny on behalf of Kingsley · Grok TTS leo · screencast skill · https://x.com/kidehen/status/2100648607712002179

Executive SummaryBy Kingsley Uyi Idehen · OpenLink Software · 2026-09-17

Synopsis

Conventional browser login UI is the wrong place to settle who may open a protected HTML document. This screencast walks four callers against one ACL-gated food-bookmark collection on URIBurner: anonymous → HTTP 401; principal WebID-TLS → 200; agent alone → 302 then 402 Payment Required at $2.99; agent with On-Behalf-Of → 200.

Verified 2026-09-17. The hero resource is addressable, governable, and sellable under Linked Open Attribute Control (LOAC) without putting credentials in a chat UI. Phenny posts on behalf of Kingsley Idehen; voice-over is Grok TTS (leo).

View this analysis as a KG entity
How-To

How-To Guide

1

Act 0 — Title frame

Confirm the subject: identity and delegation against one protected HTML document — not a login form, not a shared password.

2

Act 1 — Anonymous request

Call with no client certificate. Expect HTTP 401 Unauthorized.

3

Act 2 — Principal WebID-TLS

Present the principal PKCS#12 (label + SAN NetID only). Expect HTTP 200 OK.

4

Act 3 — Agent alone

Present the agent certificate without On-Behalf-Of. Expect 302 then 402 at $2.99.

5

Act 4 — Agent + On-Behalf-Of

Same agent certificate plus On-Behalf-Of: principal NetID. Expect HTTP 200 OK.

6

Act 5 — Scoreboard

Read the four outcomes side by side. One resource; identity and delegation decide.

FAQ

Frequently Asked Questions

Because access here is decided by cryptographic identity and delegation on the HTTP request itself. A form-based login would hide the four distinct outcomes (401 / 200 / 302→402 / OBO 200) behind a single session cookie narrative.

The food-bookmark collection snapshot HTML on linkeddata.uriburner.com under DAV/demos/daas_paid. Ordinary HTTPS uses the default port; WebID-TLS negotiations use the same path on port 5443.

HTTP 401 Unauthorized. No client certificate is presented. Digest may be advertised, but this demonstration stays on the WebID-TLS path.

Without On-Behalf-Of, the agent certificate is not the entitled principal. LOAC/MPP responds with a payment challenge (402 Payment Required, 299 cents) instead of the HTML body. Payment JWTs are redacted in the screencast.

The same agent certificate plus an On-Behalf-Of header naming the principal NetID URL. Delegation is asserted; the server returns HTTP 200 and the agent receives the resource as acting for the principal.

Only the certificate label and the SAN NetID URL. Never a passphrase, never a PEM body, never raw private key material.

Kingsley Uyi Idehen is the accountable author. Phenny posts on his behalf. Narration uses Grok TTS voice leo. The walkthrough was verified 2026-09-17.

Four outcomes, one resource: identity and delegation decide — anonymous 401, principal WebID-TLS 200, agent alone 302→402 ($2.99), agent+OBO 200.

Glossary

Glossary of Terms

ACL

Access Control List: rules that map authenticated identities (and delegated agents) to permissions on a resource. The food-bookmark HTML is ACL-gated on URIBurner.

Digital identity

Machine-verifiable claim of who is calling — here proven by WebID-TLS certificate presentation and optional On-Behalf-Of delegation, not by a shared password.

MPP / HTTP 402

Micropayment Protocol pattern using HTTP 402 Payment Required. In this demo the agent-alone path is redirected (302) then challenged with 402 at $2.99 (299 cents). Content is withheld until payment or entitled identity intervenes.

Public-key infrastructure

System of certificates, public keys, and trust anchors used to authenticate parties. WebID-TLS is a decentralized PKI pattern that binds a TLS client cert to a NetID.

Agent vs principal

The principal is the entitled identity that owns access. The agent is a separate certificate holder that may act only when On-Behalf-Of names the principal. Agent alone is not the entitled principal — hence 302→402 instead of 200.

LOAC

Linked Open Attribute Control — ACL and attribute-based access control expressed over Linked Data, so the same resource URI can enforce different outcomes for anonymous, principal, agent, and delegated callers.

NetID

Network identity HTTP URI (WebID) naming a person or agent profile document. Shown in certificate SANs as a URL; never confuse the NetID with a passphrase or PEM body.

WebID-TLS

TLS client-certificate authentication where the certificate SAN carries a WebID (NetID) HTTP URI. The server dereferences that URI to verify the public key binds to the claimed identity. No username/password form is required.

DPKI

Decentralized Public Key Infrastructure: identity and trust anchored in dereferenceable NetIDs and public keys rather than a centralized IdP login GUI. Lets protected HTML stay addressable, governable, and sellable without credentials in a chat or browser form UI.

On-Behalf-Of

HTTP header carrying the principal NetID URL so an agent certificate can assert delegation. With OBO, the agent is authorized as acting for the entitled principal; without it, the agent is treated as a non-entitled caller.

Knowledge Graph Explorer 72 nodes · 128 links

Interactive graph visualization derived from the companion RDF. Click nodes to resolve, drag to explore. Graph data embedded from companion RDF at generation time.

Same protected HTML. Four callers. Four outcomes — without the browser login UI.

Nodes: 0 Links: 0
Click SVG to activate zoom, click outside to release | Drag nodes to pin, double-click to unpin
Classes Properties Instances

SPARQL Workbench 3 sample queries

Query this knowledge graph on URIBurner. The editor opens on the canonical SAMPLE entity-type summary (DAV named graph). Pick a recipe, edit freely, then run live or copy.

Query editor

▶ Run live on URIBurner SELECT: text/x-html+tr | DESCRIBE/CONSTRUCT: text/x-html-nice-turtle