Skip to main content

HTTP Redirect Headers
draft-hardt-httpbis-redirect-headers-00

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors Dick Hardt , Sam Goto
Last updated 2026-01-05
Replaced by draft-hardt-oauth-protected-authorization
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-hardt-oauth-protected-authorization
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document defines HTTP headers that enable secure parameter passing and mutual authentication during browser redirects. The Redirect-Query header carries parameters in browser-controlled headers instead of URLs, preventing leakage through browser history, Referer headers, server logs, and analytics systems. The Redirect- Origin header provides browser-verified origin authentication that cannot be spoofed or stripped, enabling reliable mutual authentication between parties. The optional Redirect-Path header allows servers to request path-specific origin verification. Together, these headers address critical security and privacy concerns in authentication and authorization protocols such as OAuth 2.0, OpenID Connect, and SAML.

Authors

Dick Hardt
Sam Goto

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)