%% You should probably cite draft-mw-oauth-actor-chain instead of this I-D. @techreport{mw-spice-actor-chain-01, number = {draft-mw-spice-actor-chain-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-mw-spice-actor-chain/01/}, author = {A Prasad and Ramki Krishnan and Diego Lopez and Srinivasa Addepalli}, title = {{Cryptographically Verifiable Actor Chains for OAuth 2.0 Token Exchange}}, pagetotal = 62, year = , month = , day = , abstract = {This document defines five actor-chain profiles for OAuth 2.0 Token Exchange \{\{!RFC8693\}\}. \{\{!RFC8693\}\} permits nested act claims, but prior actors remain informational only and token exchange does not define how a delegation path is preserved and validated across successive exchanges. This document defines profile-specific processing for linear multi- hop workflows. The profiles are Asserted Delegation Path, Selectively Disclosed Asserted Delegation Path, Committed Delegation Path, Commitment-Only Delegation Path, and Selectively Disclosed Committed Delegation Path. These profiles preserve the existing meanings of sub and act, support same- domain and cross-domain delegation, require sender-constrained tokens, and provide different tradeoffs among readable chain-based authorization, cryptographic accountability, auditability, privacy, and long-running workflow support.}, }