Delegation (OAuth token exchange)

In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors 1. Under impersonation the actor becomes indistinguishable from the subject. An agent should hold a delegated, narrower token, never the user's own.

Developed in
ch. 23, Delegation without impersonation
Chapters
ch. 23, AI Agents
Contrast with
Delegation chain · Token passthrough
Source
1 numbered reference, listed below

Where it is used

The term is not used under this name in running prose; the sections listed under "Developed in" treat it.

Sources

  1. [1] RFC 8693, OAuth 2.0 Token Exchange (impersonation versus delegation semantics; the act (actor) claim; nested act claims record prior actors). IETF. 2020-01. https://www.rfc-editor.org/rfc/rfc8693.html (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Delegation (OAuth token exchange). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/delegation-oauth-token-exchange. CC BY 4.0

BibTeX

@misc{aige2026delegationoauthtokenexchange,
  author  = {Jorge García Aibar},
  title   = {{Delegation (OAuth token exchange)}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/delegation-oauth-token-exchange}
}