I-D Action: draft-zhu-oauth-async-delegation-02.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178469907780.371419.415087764840617307@dt-datatracker-d4d6ff9d9-fsx7d> |
Internet-Draft draft-zhu-oauth-async-delegation-02.txt is now available.
Title: Delegation Handle for Asynchronous OAuth 2.0 Token Exchange
Authors: Larry Zhu
Zate Berg
Name: draft-zhu-oauth-async-delegation-02.txt
Pages: 23
Dates: 2026-07-21
Abstract:
This document defines a standardized continuation mechanism for
delegated OAuth 2.0 Token Exchange. RFC 8693 permits an
authorization server to include an optional "refresh_token" in a
successful Token Exchange response, but does not specify issuance
policy, delegated authorization semantics, lifecycle, or security
properties for continuation credentials. This specification fills
that gap for asynchronous and long-running delegated service
workflows by defining the Delegation Handle.
The Delegation Handle is a delegation-bound continuation credential
with a new token type identifier usable as the RFC 8693
"subject_token_type". An acting service presents the handle as the
"subject_token" in a subsequent RFC 8693 Token Exchange request after
the original subject token is no longer available. This
specification standardizes delegated continuation semantics,
preservation of subject and actor relationships, audience
confinement, scope monotonicity, actor binding, authorization re-
evaluation during continuation, token rotation, revocation, bounded
delegation lifetime, and interoperability between implementations.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-zhu-oauth-async-delegation/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-zhu-oauth-async-delegation-02.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-zhu-oauth-async-delegation-02
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]