---
title: "Delegation (OAuth token exchange)"
description: "In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors."
canonical: https://aigovernanceengineer.com/glossary/delegation-oauth-token-exchange
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Delegation (OAuth token exchange)

In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors [1]. Under impersonation the actor becomes indistinguishable from the subject. An agent should hold a delegated, narrower token, never the user's own.

- Developed in: [ch. 23, Delegation without impersonation](https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation)
- Chapters: [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [Delegation chain](https://aigovernanceengineer.com/glossary/delegation-chain) · [Token passthrough](https://aigovernanceengineer.com/glossary/token-passthrough)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-delegation-oauth-token-exchange

## Sources

[1] RFC 8693, OAuth 2.0 Token Exchange (impersonation versus delegation semantics; the act (actor) claim; nested act claims record prior actors). IETF. 2020-01. https://www.rfc-editor.org/rfc/rfc8693.html (verified: primary)
