Option 2: OIDF Shared signals
- OIDF Shared Signals ID-2
- Supports PUSH and PULL mode
- Allows sending of IETF Security Events
- Profile of IETF SET and IETF SET Delivery Methods
- Defines well-known for SSF configuration
- Defines request/response structures
- Defines endpoints
- Discuss
- Would it make sense to reuse OIDF shared signals and define a new profile for SET for OID4VCI events?
- PUSH endpoint protection uses static authorization header which might not be great, e.g., does not support DPoP?