@a1ba authorization mechanism but on specific URIs (bearer capabilities URI,)
you attach a token to an URI, when dereferencing it you send that token
i’m guessing it’s used to be revoked in specific circumstances but i don’t really see the point considering how everything else works in AP