@helene ocaps are for when you hate acls and want proof by possession instead of proof by identity
think of like... you could make a youtube video "private" (acl limited to specific authenticated accounts) or you could make it "unlisted" (with a sufficiently unguessable url, the url becomes a secure token, but you don't need an account)
they're not "weaker" they just have different properties. ocaps tend to be simpler to check and more flexible in what they provide (see: attenuation of ocaps)