An important area I want to research is delegation and attenuation of authz tokens. However, some of this work needs to cook a bit more.
I want to write up the latest proposal (with parent web token / child key attributes for the header), but separate it out from the existing verification documents so we can proceed with that material.