Decentralized Public Key Infrastructure (DPKI) puts the conventional browser GUI out of the way. Identity and On-Behalf-Of delegation decide access.
David Ogilvy sold with specifics, not adjectives. Here are four HTTP outcomes against the same ACL-gated food-bookmark HTML — verified 2026-09-17 — with the conventional browser login UI kept out of the way.
Hero resource (WebID-TLS on :5443): https://linkeddata.uriburner.com/DAV/demos/daas_paid/food-bookmark-collection-snapshot-2026-09-08.html
| Caller | Identity presented | HTTP outcome | Meaning |
|---|---|---|---|
| Anonymous | No client certificate | 401 Unauthorized | Denied |
| Principal WebID-TLS | Principal PKCS#12 — label + SAN NetID only | 200 OK | Entitled principal |
| Agent alone | Agent certificate; no On-Behalf-Of | 302 → 402 ($2.99) | MPP / 402 challenge |
| Agent + On-Behalf-Of | Agent cert + OBO: principal NetID URL | 200 OK | Delegated access |
DPKI insight. Decentralized Public Key Infrastructure makes protected HTML addressable, governable, and sellable without putting credentials in a chat UI. LOAC maps the four callers to four outcomes on one URI. Certificate label and SAN NetID only — never a passphrase, never a PEM body; payment JWTs redacted.
Attribution: Phenny on behalf of Kingsley · Grok TTS leo · screencast skill · https://x.com/kidehen/status/2100648607712002179
Conventional browser login UI is the wrong place to settle who may open a protected HTML document. This screencast walks four callers against one ACL-gated food-bookmark collection on URIBurner: anonymous → HTTP 401; principal WebID-TLS → 200; agent alone → 302 then 402 Payment Required at $2.99; agent with On-Behalf-Of → 200.
Verified 2026-09-17. The hero resource is addressable, governable, and sellable under Linked Open Attribute Control (LOAC) without putting credentials in a chat UI. Phenny posts on behalf of Kingsley Idehen; voice-over is Grok TTS (leo).
Confirm the subject: identity and delegation against one protected HTML document — not a login form, not a shared password.
Call with no client certificate. Expect HTTP 401 Unauthorized.
Present the principal PKCS#12 (label + SAN NetID only). Expect HTTP 200 OK.
Present the agent certificate without On-Behalf-Of. Expect 302 then 402 at $2.99.
Same agent certificate plus On-Behalf-Of: principal NetID. Expect HTTP 200 OK.
Read the four outcomes side by side. One resource; identity and delegation decide.
Because access here is decided by cryptographic identity and delegation on the HTTP request itself. A form-based login would hide the four distinct outcomes (401 / 200 / 302→402 / OBO 200) behind a single session cookie narrative.
The food-bookmark collection snapshot HTML on linkeddata.uriburner.com under DAV/demos/daas_paid. Ordinary HTTPS uses the default port; WebID-TLS negotiations use the same path on port 5443.
HTTP 401 Unauthorized. No client certificate is presented. Digest may be advertised, but this demonstration stays on the WebID-TLS path.
Without On-Behalf-Of, the agent certificate is not the entitled principal. LOAC/MPP responds with a payment challenge (402 Payment Required, 299 cents) instead of the HTML body. Payment JWTs are redacted in the screencast.
The same agent certificate plus an On-Behalf-Of header naming the principal NetID URL. Delegation is asserted; the server returns HTTP 200 and the agent receives the resource as acting for the principal.
Only the certificate label and the SAN NetID URL. Never a passphrase, never a PEM body, never raw private key material.
Kingsley Uyi Idehen is the accountable author. Phenny posts on his behalf. Narration uses Grok TTS voice leo. The walkthrough was verified 2026-09-17.
Four outcomes, one resource: identity and delegation decide — anonymous 401, principal WebID-TLS 200, agent alone 302→402 ($2.99), agent+OBO 200.
Access Control List: rules that map authenticated identities (and delegated agents) to permissions on a resource. The food-bookmark HTML is ACL-gated on URIBurner.
Machine-verifiable claim of who is calling — here proven by WebID-TLS certificate presentation and optional On-Behalf-Of delegation, not by a shared password.
Micropayment Protocol pattern using HTTP 402 Payment Required. In this demo the agent-alone path is redirected (302) then challenged with 402 at $2.99 (299 cents). Content is withheld until payment or entitled identity intervenes.
System of certificates, public keys, and trust anchors used to authenticate parties. WebID-TLS is a decentralized PKI pattern that binds a TLS client cert to a NetID.
The principal is the entitled identity that owns access. The agent is a separate certificate holder that may act only when On-Behalf-Of names the principal. Agent alone is not the entitled principal — hence 302→402 instead of 200.
Linked Open Attribute Control — ACL and attribute-based access control expressed over Linked Data, so the same resource URI can enforce different outcomes for anonymous, principal, agent, and delegated callers.
Network identity HTTP URI (WebID) naming a person or agent profile document. Shown in certificate SANs as a URL; never confuse the NetID with a passphrase or PEM body.
TLS client-certificate authentication where the certificate SAN carries a WebID (NetID) HTTP URI. The server dereferences that URI to verify the public key binds to the claimed identity. No username/password form is required.
Decentralized Public Key Infrastructure: identity and trust anchored in dereferenceable NetIDs and public keys rather than a centralized IdP login GUI. Lets protected HTML stay addressable, governable, and sellable without credentials in a chat or browser form UI.
HTTP header carrying the principal NetID URL so an agent certificate can assert delegation. With OBO, the agent is authorized as acting for the entitled principal; without it, the agent is treated as a non-entitled caller.
Interactive graph visualization derived from the companion RDF. Click nodes to resolve, drag to explore. Graph data embedded from companion RDF at generation time.
Query this knowledge graph on URIBurner. The editor opens on the canonical SAMPLE entity-type summary (DAV named graph). Pick a recipe, edit freely, then run live or copy.