In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors 1. Under impersonation the actor becomes indistinguishable from the subject. An agent should hold a delegated, narrower token, never the user's own.
- Developed in
- ch. 23, Delegation without impersonation
- Chapters
- ch. 23, AI Agents
- Contrast with
- Delegation chain · Token passthrough
- Source
- 1 numbered reference, listed below
Where it is used
The term is not used under this name in running prose; the sections listed under "Developed in" treat it.
Sources
- [1] RFC 8693, OAuth 2.0 Token Exchange (impersonation versus delegation semantics; the act (actor) claim; nested act claims record prior actors). IETF. 2020-01. https://www.rfc-editor.org/rfc/rfc8693.html (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .