@techreport{ietf-oauth-identity-assertion-authz-grant-04, number = {draft-ietf-oauth-identity-assertion-authz-grant-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant/04/}, author = {Aaron Parecki and Karl McGuinness and Brian Campbell}, title = {{Identity Assertion JWT Authorization Grant}}, pagetotal = 65, year = 2026, month = may, day = 21, abstract = {This specification provides a mechanism for an application to use an identity assertion to obtain an access token for a third-party API by coordinating through an identity provider that the downstream Resource Authorization Server already trusts for single sign-on (SSO), using Token Exchange {[}RFC8693{]} and JWT Profile for OAuth 2.0 Authorization Grants {[}RFC7523{]}. This pattern is informally referred to as Cross-App Access (XAA).}, }