%% You should probably cite draft-araut-oauth-transaction-tokens-for-agents-02 instead of this revision. @techreport{araut-oauth-transaction-tokens-for-agents-00, number = {draft-araut-oauth-transaction-tokens-for-agents-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-araut-oauth-transaction-tokens-for-agents/00/}, author = {Ashay Raut}, title = {{Transaction Tokens For Agents}}, pagetotal = 19, year = , month = , day = , abstract = {This document specifies an extension to the OAUTH-TXN-TOKENS (https://drafts.oauth.net/oauth-transaction-tokens/draft-ietf-oauth- transaction-tokens.html) to support agent context propagation within Transaction Tokens for agent-based workloads. The extension defines the use of the act field to identify the agent performing the action, and leverages the existing sub field (as defined in the base Transaction Tokens specification) to represent the principal. The sub field is populated according to the rules specified in OAUTH-TXN- TOKENS (https://drafts.oauth.net/oauth-transaction-tokens/draft-ietf- oauth-transaction-tokens.html), based on the 'subject\_token' provided in the token request. For autonomous agents operating independently, the sub field represents the agent itself. These mechanisms enable services within the call graph to make more granular access control decisions, thereby enhancing security.}, }