RFC 7616: HTTP Digest Access Authentication
In plain English — editorial summary, not part of the RFC
The Hypertext Transfer Protocol (HTTP) provides a simple challenge- response authentication mechanism that may be used by a server to challenge a client request and by a client to provide authentication information. This document defines the HTTP Digest Authentication scheme that can be used with the HTTP authentication mechanism.
Document record
- Document ID
- RFC7616
- Published
- September 2015
- Authors
- R. Shekh-Yusef; D. Ahrens; S. Bremer
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 32
- Also known as
- —
- Obsoletes:
- RFC 2617
Topics
Standards lineage
This document is one revision in a chain of 21 RFCs, each formally replacing the one before it.
- RFC 2068 (1997)
- RFC 2069 (1997)
- RFC 2145 (1997)
- RFC 2616 (1999)
- RFC 2617 (1999)
- RFC 2818 (2000)
- RFC 7230 (2014)
- RFC 7231 (2014)
- RFC 7232 (2014)
- RFC 7233 (2014)
- RFC 7234 (2014)
- RFC 7235 (2014)
- RFC 7238 (2014)
- RFC 7538 (2015)
- RFC 7615 (2015)
- RFC 7616 (2015)
- RFC 7617 (2015)
- RFC 7694 (2015)
- RFC 9110 (2022)
- RFC 9111 (2022)
- RFC 9112 (2022) ✓
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7617The 'Basic' HTTP Authentication SchemeCurrent
September 2015
- RFC 7236Initial Hypertext Transfer Protocol (HTTP) Authentication Scheme RegistrationsCurrent
June 2014
- RFC 7804Salted Challenge Response HTTP Authentication MechanismCurrent
March 2016
- RFC 8120Mutual Authentication Protocol for HTTPCurrent
April 2017
- RFC 8121Mutual Authentication Protocol for HTTP: Cryptographic Algorithms Based on the Key Agreement Mechanism 3 (KAM3)Current
April 2017
- RFC 6819OAuth 2.0 Threat Model and Security ConsiderationsUpdated
January 2013
- RFC 6331Moving DIGEST-MD5 to HistoricCurrent
July 2011
- RFC 9810Internet X.509 Public Key Infrastructure -- Certificate Management Protocol (CMP)Current
July 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?