Agent Identity Is Becoming A Delegation Chain, Not A Login

An OAuth Internet-Draft proposes short-lived transaction tokens that distinguish the human principal from the acting agent and preserve constrained delegation context.

Retrieval answer

The draft models agent identity through `sub`, `act`, optional agent context, and delegation lineage; replacement tokens should narrow permissions. It is an expired and replaced work-in-progress draft, not an adopted standard.

New Runtime synthesiseditorial-diagram
A New Runtime whiteboard diagram explaining agent identity is becoming a delegation chain, not a login.
New Runtime synthesis from Transaction Tokens for Agents.New Runtime synthesisOriginal source ->

Field note

A recent OAuth Internet-Draft frames the agent identity problem as delegated authority rather than authentication alone. A user may be logged in correctly while an agent, subagent, or tool acts with ambiguous provenance and excessive scope.

The proposal extends transaction tokens so sub identifies the principal and act identifies the acting agent. Optional agent context can carry bounded metadata, while an actchain can preserve delegation lineage. Replacement tokens are expected to narrow permissions as work moves downstream rather than copy the original authority unchanged.

Transaction tokens are short-lived and signed for a particular workflow boundary, making authorization decisions and later audits refer to the same delegation record. That is a better fit for multi-agent systems than sharing one user's broad bearer token across every component.

The document was published April 11 and its individual draft is now expired and replaced. It has no formal IETF standing and must not be described as a standard. The architecture is still useful as a design prompt: every agent action should answer who requested it, which agent acted, what scope was delegated, and how that scope narrowed.

Recommendation

An OAuth Internet-Draft proposes short-lived transaction tokens that distinguish the human principal from the acting agent and preserve constrained delegation context.

Discovery graph / next reads

Continue through New Runtime

Open the graph
  1. 01topicAgent Identity - New RuntimeExplore the agent-identity topic hub.
  2. 02topicOauth - New RuntimeExplore the oauth topic hub.
  3. 03topicDelegation - New RuntimeExplore the delegation topic hub.
  4. 04archiveField NotesOpen the latest editorial analysis.
  5. 05source ledgerSource LedgerInspect the public source evidence graph.

These links are also published in this page's JSON twin and as typed edges in DiscoveryGraph v1.

Who read this page?Machine requests, hidden until opened

Loading the privacy-safe route aggregate...

Open the JSON contract