@techreport{fletcher-transaction-token-chaining-profile-02, number = {draft-fletcher-transaction-token-chaining-profile-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-fletcher-transaction-token-chaining-profile/02/}, author = {George Fletcher and Pieter Kasselman and Sean O'Dell}, title = {{Transaction Token Authorization Grant Profile for OAuth Identity and Authorization Chaining}}, pagetotal = 31, year = 2026, month = jul, day = 6, abstract = {This specification defines a profile of the OAuth Identity and Authorization Chaining Across Domains {[}I-D.ietf-oauth-identity-chaining{]} mechanism that uses a Transaction Token (Txn-Token) {[}I-D.ietf-oauth-transaction-tokens{]} as the subject token in a Token Exchange {[}RFC8693{]} request to obtain a JWT Authorization Grant for crossing a trust boundary. A Txn-Token is scoped to a single trust domain and represents the full authorization context of an in-progress transaction, regardless of whether that transaction was initiated by a human user calling an external API, by an internal system event, or by an automated workload. This profile specifies how a service operating within that trust domain can present its Txn-Token to obtain a JWT Authorization Grant that carries the necessary context across a trust boundary, enabling an access token to be issued for a partner service, without exposing internal trust-domain credentials or token formats beyond the trust boundary.}, }