Overview#
Sec-Token-Binding HTTP Request HTTP Header Field defined in the Token Binding over HTTPOnce a client and server have negotiated the Token Binding Protocol with HTTP/1.1 or HTTP/2 (see The Token Binding Protocol and Token Binding Protocol Negotiation), clients MUST include a Sec-Token-Binding header field in their HTTP Requests, and MUST include only one such header field per HTTP Request. Also, The Sec-Token-Binding field MUST NOT be included in HTTP Responses.
The ABNF of the Sec-Token-Binding header field is (in RFC 7230 style, see also RFC 7231 Section 8.3):
Sec-Token-Binding = EncodedTokenBindingMessage