Skip to main content
Current Datatracker draft: draft-mishra-oauth-agent-grants-02 Prepared source candidate: draft-mishra-oauth-agent-grants-03 Target: IETF OAuth Working Group (oauth@ietf.org) Status: Active individual Internet-Draft; not IETF-endorsed and not OAuth WG-adopted Author contacts: mishra.sanjeev@gmail.com (primary) and sanjeev@orchestrum.in (alternate) The authoritative record is the IETF Datatracker. An individual Internet-Draft is not endorsed by the IETF and has no formal standards standing unless the working group adopts it and the standards process advances it. Revision -02 was posted on 2026-08-30. Revision -03 is a repository candidate and will not appear on the Datatracker until it is uploaded and confirmed through the IETF submission flow. The source repository now contains self-assessed client, authorization-server, and resource-server implementations of the candidate profile, with unit and Docker E2E evidence. This is not independent certification or IETF endorsement.
Submission hold: Revision -03 must not be uploaded before 2026-09-09. A final review is scheduled for 2026-09-06 through 2026-09-09, followed by a new explicit approval. No automated submission is authorized.

Implementation Snapshot

See the OAuth Agent Grants implementation guide for the hosted endpoint map, flow, operational requirements, and published-SDK boundary.

Document

The Internet-Draft source is written in kramdown-rfc2629 format, a Markdown superset that compiles to RFC XML and from there to canonical IETF text and HTML. The prepared revision source is at docs/ietf-draft/draft-mishra-oauth-agent-grants-03.md. The implementation report is at docs/ietf-draft/implementation-report.md.

Revision 03 Focus

  • Explicit conformance roles and RFC 8414 authorization-server metadata.
  • DPoP as mandatory to implement, including authorization-code binding through PAR.
  • RFC 9207 authorization-response issuer validation for mix-up defense.
  • Exact, same-instance and same-resource scope attenuation through RFC 8693 Token Exchange.
  • RFC 7009 revocation with refresh-family invalidation.
  • Precise cnf.jkt and cnf."x5t#S256" sender-confirmation members.
  • Lost-response refresh recovery clearly marked as non-interoperable implementation guidance.
  • Direct comparison with current OAuth agent authorization, attenuation, identity-chaining, and transaction-token work.

Rendering Locally

If local tooling is unavailable, use the IETF Author Tools renderer.

Submitting to the Datatracker

The following procedure is intentionally inactive until the submission hold has ended, the final artifacts have passed review, and a new explicit approval has been recorded.
  1. Set the draft date to the actual upload date and render draft-mishra-oauth-agent-grants-03.xml.
  2. Go to datatracker.ietf.org/submit.
  3. Upload draft-mishra-oauth-agent-grants-03.xml or .txt.
  4. Confirm via the email link sent to the author address.
  5. Verify that the Datatracker page shows revision -03.

Working Group Follow-Up

After the Datatracker accepts -03, announce it on the OAuth WG mailing list: The main ask should be technical review of scope and overlap:
  • Should DAAP remain a single profile or be split into smaller OAuth drafts?
  • Which parts should align with identity chaining and transaction-token work?
  • Is DPoP mandatory to implement the right sender-constraint baseline?
  • Is same-resource, exact-scope attenuation narrow enough for a first profile?
  • Should the OAuth WG discuss DAAP at IETF 127?

Dates

  • -02 expiry: 2027-03-03
  • IETF 127: 2026-11-14 through 2026-11-20, San Francisco
  • BOF proposal cutoff: 2026-09-18
  • WG meeting request cutoff: 2026-10-02
  • IETF 127 I-D submission cutoff: 2026-11-02 23:59 UTC

Path to Standards Track

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on August 31, 2026