I-D Action: draft-mcguinness-oauth-id-continuation-assertion-01.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178771725264.663131.11229508049815645876@dt-datatracker-786f84c586-97d96> |
Internet-Draft draft-mcguinness-oauth-id-continuation-assertion-01.txt is now available. Title: Identity Continuation Assertion for OAuth 2.0 Token Exchange Author: Karl McGuinness Name: draft-mcguinness-oauth-id-continuation-assertion-01.txt Pages: 60 Dates: 2026-08-25 Abstract: This document defines the Identity Continuation Assertion, a short- lived, sender-constrained JWT used as an OAuth 2.0 Token Exchange subject token. It lets an IdP Authorization Server (IdP) issue an onward Identity Assertion JWT Authorization Grant (ID-JAG) when a user's request crosses service boundaries after the user is no longer present. The profile targets deployments in which several Resource Authorization Servers trust one IdP and use audience-local subject identifiers that only the IdP can resolve. It complements offline attenuation for intra-domain fan-out that does not change the subject. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-mcguinness-oauth-id-continuation-assertion/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-mcguinness-oauth-id-continuation-assertion-01.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-mcguinness-oauth-id-continuation-assertion-01 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]