@thisismissem n.b.3 i'm kinda sad we ended up with HTTP Signatures instead of something better, I wanted to do something with OAuth2 which I still think would have been cleaner in practice