# Table of contents:
# Introduction
WEB is a authentication scheme available since MSNP16.
Instead of sending any authentication information at all,
WEB uses the headers sent in HTTP requests of HTTP Gateway sessions.
In particular, WEB will use the X-MSN-Auth to determine the token location:
Use-Cookie: Use theRPSTAuth(RPS) orMSPAuthandMSPProf(PPM) cookies.Use-X-MSN-SslAuthToken: Use the contents of theX-MSN-SslAuthTokenheader.
# Procedure
The client sends the USR request, and gets an OK response:
C: USR TrID WEB
S: USR TrID OK (...)