Thibault suggests to add a section on "Best Practices" or "Operational Considerations" advising that the HTTP endpoint hosting the JAFAR file MUST be publicly available and SHOULD NOT require authentication (avoiding 401/403 errors) to ensure utility.
Reference:
https://mailarchive.ietf.org/arch/msg/web-bot-auth/Yqw0r8Ry2I6wqB5huKxUQs-ApLE/