Neat, didn't notice that SCRAM for HTTP Authentication was a standardized thing until now: https://datatracker.ietf.org/doc/html/rfc7804Apparently authored by an employee of an XMPP software vendor.