topic Registered
Verified 2026-09-19 · registry updated 2017-04-13

HTTP registry: no-auth

Registered value from the IANA HTTP registry.

Authentication registry values define how a client proves identity or possession of credentials to an origin or proxy. no-auth is registered in HTTP Authentication Control Parameters. Defining reference: RFC8053, Section 4.4.

httpregistryhttp-authentication-control-parametersauthentication-control-parameters

Identifier (http)

no-auth

Registered value from the IANA HTTP registry.

Use TLS, validate issuer/audience or challenge parameters, scope credentials to the correct hop, and design expiry, rotation, and replay handling explicitly.

This registry value is currently marked active by IANA. Follow the defining specification before sending, accepting, or proxying it.

IANA registry: http-authentication-control-parameters/authentication-control-parameters

Registry reference: RFC8053, Section 4.4

Permalink: https://merginit.com/reference/http/registry/http-authentication-control-parameters/authentication-control-parameters/no-auth-11