Skip to main content

Cryptographically Verifiable Actor Chains for OAuth 2.0 Token Exchange
draft-mw-spice-actor-chain-05

Document Type Replaced Internet-Draft (individual)
Expired & archived
Authors A Prasad , Ramki Krishnan , Diego Lopez , Srinivasa Addepalli
Last updated 2026-04-25
Replaced by draft-mw-oauth-actor-chain
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-mw-oauth-actor-chain
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Multi-hop service-to-service and agentic workflows need a standardized way to preserve and validate delegation-path continuity across successive token exchanges. This document defines six actor- chain profiles for OAuth 2.0 Token Exchange [RFC8693]. [RFC8693] permits nested act claims, but prior actors remain informational only and token exchange does not define how a delegation path is preserved and validated across successive exchanges. This document profiles delegation-chain tokens and defines profile- specific processing for multi-hop workflows. The six profiles are: Declared Full Disclosure; Declared Subset Disclosure; Declared Actor- Only Disclosure; Verified Full Disclosure; Verified Subset Disclosure; and Verified Actor-Only Disclosure. These profiles preserve the existing meanings of sub, act, and may_act. They support same-domain and cross-domain delegation and provide different tradeoffs among visible chain-based authorization, cryptographic accountability, auditability, privacy, and long-running workflow support. Plain RFC 8693 impersonation-shaped outputs remain valid RFC 8693 behavior but are outside this profile family.

Authors

A Prasad
Ramki Krishnan
Diego Lopez
Srinivasa Addepalli

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)