@techreport{hardt-aauth-r3-00, number = {draft-hardt-aauth-r3-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hardt-aauth-r3/00/}, author = {Dick Hardt}, title = {{AAuth Rich Resource Requests (R3)}}, pagetotal = 40, year = 2026, month = sep, day = 28, abstract = {This document defines AAuth Rich Resource Requests (R3), an extension to the AAuth Protocol ({[}I-D.hardt-oauth-aauth-protocol{]}) that enables structured, vocabulary-based authorization for resource access. Resources publish R3 documents (content-addressed authorization definitions) and advertise vocabularies describing their operations. Agents request access using those vocabularies. Auth tokens carry granted operations in the same vocabulary format, enabling resources to enforce authorization directly from the token. Resources annotate individual operations in their vocabulary with the credential each requires, so an agent can plan before its first call. R3 provides human-displayable context for consent decisions and content-addressed audit provenance via the r3\_s256 hash in auth tokens.}, }