(registered 2026-10-06, last updated 2026-10-06) Media type name: application Media subtype name: vnd.emilia.authorization-evidence-challenge+json Required parameters: N/A Optional parameters: N/A Encoding considerations: binary The content is one UTF-8 JSON text whose top-level value is a single `AE-CHALLENGE-v1` object. It is not a JSON text sequence and does not use record-separator framing. Binary is selected because JSON representations can contain lines longer than 998 octets. Security considerations: This media type contains declarative JSON and no active or executable content. It uses neither compression nor a container format. It provides no origin authentication, integrity, confidentiality, replay protection, trusted time, or audience verification; a carrier or authenticated envelope must supply the properties required by its use. A challenge authorizes nothing and does not reserve or consume action authority, promise execution, or establish that an external effect occurred. The object contains URI-valued semantic identifiers and may contain `obtain_hints`. Dereferencing is not required for parsing. Security-relevant URI semantics must be locally pinned or resolved only from immutable, authenticated content. `obtain_hints` are untrusted inputs and can create SSRF, redirect, credential-forwarding, and evidence-exfiltration risks. Single-use processing requires an authoritative replay domain keyed by authenticated issuer identity and nonce and an atomic first-claim transition; expiry and nonce randomness alone do not prevent replay. Implementations reject duplicate JSON members, enforce finite parsing and state limits, and fail closed on replay-store uncertainty. Action and policy digests do not hide low-entropy values and do not prove business correctness or execution. Confidentiality appropriate to the deployment is required when the challenge exposes sensitive action, policy, identity, or routing information. See RFC 8259 Section 12 and Sections 2.2--2.8 and 5 of draft-schrock-ae-challenge-07. Interoperability considerations: The representation is exactly one UTF-8 RFC 8259 JSON text containing a single `AE-CHALLENGE-v1` core object. Generic `+json` processors can parse the syntax but do not thereby implement challenge semantics. Recipients refuse an unsupported `@version` and duplicate members; nested core objects are closed; `critical` governs unknown top-level extensions. This media type labels the bare core object, not an RFC 9457 Problem Details wrapper. It does not select a canonicalization profile; every carrier binding or presentation profile must define the complete-body digest and representation, issuer identity, audience, replay domain, time, and return-path semantics required by the underlying data model. Published specification: EMILIA bare AE Challenge media-type serialization specification, Version 1: https://github.com/emiliaprotocol/emilia-protocol/blob/main/standards/iana/ae-challenge-vendor-binding.md Underlying data model, work in progress: https://www.ietf.org/archive/id/draft-schrock-ae-challenge-07.html Relevant sections: 2, 2.7, 2.8, and 5. This registration defines the vendor media type for the bare JSON serialization. It is not the HTTP carrier in Section 3. Applications which use this media: This media type is intended for use by EMILIA product implementations and compatible presenters that exchange a bare `AE-CHALLENGE-v1` object through a separately specified carrier or presentation profile. Fragment identifier considerations: As specified for `+json` in RFC 6839 Section 3.1. Because `application/json` defines no fragment-identifier syntax, this registration defines none. Restrictions on usage: This type labels only the bare `AE-CHALLENGE-v1` core object. It MUST NOT be used as the `Content-Type` of the HTTP refusal response defined by Section 3 of draft-schrock-ae-challenge-07, which remains `application/problem+json` and carries the core object in `evidence_challenge`. Any carrier or presentation profile must satisfy the applicable requirements in Sections 2 and 2.8. Additional information: 1. Deprecated alias names for this type: N/A 2. Magic number(s): N/A 3. File extension(s): N/A 4. Macintosh file type code: N/A 5. Object Identifiers: N/A General Comments: This is a vendor-tree product registration for the bare `AE-CHALLENGE-v1` JSON object. It does not request a standards-tree allocation and does not change the HTTP carrier in draft-schrock-ae-challenge-07, which uses `application/problem+json`. The vendor designation `emilia` refers to EMILIA Protocol, Inc. Person to contact for further information: 1. Name: Iman Schrock 2. Email: team&emiliaprotocol.ai Intended usage: LIMITED USE Author/Change controller: Iman Schrock, EMILIA Protocol, Inc. . Change controller: EMILIA Protocol, Inc. .