Interesting, that would be a good addition, but I could see use cases where clients would want to re-AUTH against clients many times in a single session
Discussion
Yes, I would propose it as an additional option. Could be the same signed event in a jwt without the challenge string or something for a header.
I don’t see why the NIP couldn’t support both!