@techreport{liu-oauth-rego-policy-00, number = {draft-liu-oauth-rego-policy-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-liu-oauth-rego-policy/00/}, author = {Dapeng Liu and Judy Zhu and Suresh Krishnan and Aaron Parecki and Hui Xue}, title = {{Rego Policy Language for OAuth 2.0 Authorization}}, pagetotal = 34, year = 2026, month = jun, day = 12, abstract = {AI agents exhibit dynamic, unpredictable behavior that cannot be fully described by traditional OAuth 2.0 scopes. This specification defines a behavioral authorization framework that enables clients, particularly AI agents, to propose Rego policy-based behavioral constraint contracts in OAuth 2.0 authorization flows using Rich Authorization Requests (RAR). It defines the rego\_policy authorization data type for carrying behavioral constraint contracts in authorization\_details, shifting the authorization model from static permission sets to runtime behavioral verification. It also defines a reverse-guided authorization mechanism allowing resource servers to return structured policy constraints in error responses, enabling agents to dynamically adapt their behavior and construct appropriate authorization requests.}, }