Section 1's standards table addresses UMA and GNAP in two brief rows, and both read as if PDPP were choosing a foundation from among authorization protocols. That framing no longer matches the specification: the core artifacts (the grant, the record model, the read surface) are defined so they do not depend on any single authorization protocol, with OAuth 2.0 + RFC 9396 as the v0.1 binding.
Proposed change, confined to wording in "Relationship to existing standards":
- GNAP row: remove the statement that a future version should evaluate whether GNAP is "a better foundation." State instead that PDPP is designed to be compatible with different authorization protocols; OAuth 2.0 + RFC 9396 is the deployed binding for v0.1, and other bindings, including GNAP, are possible as adoption warrants.
- UMA row: keep the prior-art acknowledgment for the user-managed, standing, revocable access model, and make the relationship explicit: PDPP adopts that access model and delivers it over the OAuth line deployed today.
No structural changes to the specification.
Section 1's standards table addresses UMA and GNAP in two brief rows, and both read as if PDPP were choosing a foundation from among authorization protocols. That framing no longer matches the specification: the core artifacts (the grant, the record model, the read surface) are defined so they do not depend on any single authorization protocol, with OAuth 2.0 + RFC 9396 as the v0.1 binding.
Proposed change, confined to wording in "Relationship to existing standards":
No structural changes to the specification.