%% You should probably cite draft-hardt-oauth-aauth-protocol instead of this I-D. @techreport{hardt-aauth-protocol-02, number = {draft-hardt-aauth-protocol-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hardt-aauth-protocol/02/}, author = {Dick Hardt}, title = {{AAuth Protocol}}, pagetotal = 104, year = 2026, month = apr, day = 28, abstract = {This document defines the AAuth authorization protocol for agent-to- resource authorization and identity claim retrieval. The protocol supports four resource access modes — identity-based, resource- managed (two-party), PS-managed (three-party), and federated (four- party) — with agent governance as an orthogonal layer. It builds on the HTTP Signature Keys specification ({[}I-D.hardt-httpbis-signature-key{]}) for HTTP Message Signatures and key discovery.}, }