I-D Action: draft-asor-wimse-agent-delegation-chain-00.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178782103413.841673.7712745866254325123@dt-datatracker-786f84c586-vck88> |
Internet-Draft draft-asor-wimse-agent-delegation-chain-00.txt is now available. Title: Verifiable Attenuated Delegation for AI Agent Chains Author: Rafael Asor Name: draft-asor-wimse-agent-delegation-chain-00.txt Pages: 12 Dates: 2026-08-27 Abstract: AI agents increasingly delegate tasks to other agents. Each delegation should convey only a subset of the delegating party's authority, that subset should be bounded in scope, magnitude, and time, and any enforcement point should be able to verify -- offline, with no call to an authorization server -- that a token presented at hop N carries authority no greater than the token at hop N-1, back to a trusted root. OAuth 2.0 Token Exchange (RFC 8693) models two-party delegation and records prior actors in a nested "act" claim, but that claim is informational only and cannot enforce attenuation across a chain of depth two or more. This document defines the Agent Delegation Chain: a profile of OAuth 2.0 JWT access tokens (RFC 9068) that carries authority as Rich Authorization Requests (RFC 9396), links each delegation to its parent by a cryptographic byte- commitment, and specifies a deterministic offline verification algorithm that enforces monotonic attenuation, bounded depth, and monotonic expiry. It reuses existing JOSE, proof-of-possession (RFC 9449), and status-list machinery (the OAuth Status List draft) and introduces no new cryptography. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-asor-wimse-agent-delegation-chain/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-asor-wimse-agent-delegation-chain-00.html Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]