diff --git a/index.html b/index.html index 3b2ff25..1ab0874 100644 --- a/index.html +++ b/index.html @@ -565,11 +565,50 @@

Authorization

require conforming VC API clients to utilize secure authorization technologies when performing certain types of requests. Each HTTP endpoint defined in this document specifies whether or not authorization is required -when performing a request. +when performing a request. With the exception of the class of forbidden +authorization protocols discussed later in this section, the VC API is agnostic +regarding authorization mechanism.

-This section details the authorization technologies that have been contemplated -for use by conforming implementations. Other equivalent authorization +The VC API is meant to be generic and useful in many scenarios that require +the issuance, possession, presentation, and/or verification of Verifiable +Credentials. To this end, implementers are advised to consider the following +classifications of use cases: +

+ +

+The rest of this section gives examples of the authorization technologies that have +been contemplated for use by conforming implementations. Other equivalent authorization technologies can be used. Implementers are cautioned against using non-standard or legacy authorization technologies.