draft-mishra-oauth-agent-grants-02
Prepared source candidate: draft-mishra-oauth-agent-grants-03
Target: IETF OAuth Working Group (oauth@ietf.org)
Status: Active individual Internet-Draft; not IETF-endorsed and not OAuth WG-adopted
Author contacts: mishra.sanjeev@gmail.com (primary) and sanjeev@orchestrum.in (alternate)
The authoritative record is the IETF Datatracker. An individual Internet-Draft is not endorsed by the IETF and has no formal standards standing unless the working group adopts it and the standards process advances it.
Revision -02 was posted on 2026-08-30. Revision -03 is a repository candidate and will not appear on the Datatracker until it is uploaded and confirmed through the IETF submission flow. The source repository now contains self-assessed client, authorization-server, and resource-server implementations of the candidate profile, with unit and Docker E2E evidence. This is not independent certification or IETF endorsement.
Submission hold: Revision -03 must not be uploaded before 2026-09-09. A final review is scheduled for 2026-09-06 through 2026-09-09, followed by a new explicit approval. No automated submission is authorized.
Implementation Snapshot
See the OAuth Agent Grants implementation guide
for the hosted endpoint map, flow, operational requirements, and published-SDK
boundary.
Document
The Internet-Draft source is written in kramdown-rfc2629 format, a Markdown superset that compiles to RFC XML and from there to canonical IETF text and HTML. The prepared revision source is atdocs/ietf-draft/draft-mishra-oauth-agent-grants-03.md. The implementation report is at docs/ietf-draft/implementation-report.md.
Revision 03 Focus
- Explicit conformance roles and RFC 8414 authorization-server metadata.
- DPoP as mandatory to implement, including authorization-code binding through PAR.
- RFC 9207 authorization-response issuer validation for mix-up defense.
- Exact, same-instance and same-resource scope attenuation through RFC 8693 Token Exchange.
- RFC 7009 revocation with refresh-family invalidation.
- Precise
cnf.jktandcnf."x5t#S256"sender-confirmation members. - Lost-response refresh recovery clearly marked as non-interoperable implementation guidance.
- Direct comparison with current OAuth agent authorization, attenuation, identity-chaining, and transaction-token work.
Rendering Locally
Submitting to the Datatracker
The following procedure is intentionally inactive until the submission hold has ended, the final artifacts have passed review, and a new explicit approval has been recorded.- Set the draft date to the actual upload date and render
draft-mishra-oauth-agent-grants-03.xml. - Go to datatracker.ietf.org/submit.
- Upload
draft-mishra-oauth-agent-grants-03.xmlor.txt. - Confirm via the email link sent to the author address.
- Verify that the Datatracker page shows revision
-03.
Working Group Follow-Up
After the Datatracker accepts-03, announce it on the OAuth WG mailing list:
- List:
oauth@ietf.org - Archive: mailarchive.ietf.org/arch/browse/oauth
- Should DAAP remain a single profile or be split into smaller OAuth drafts?
- Which parts should align with identity chaining and transaction-token work?
- Is DPoP mandatory to implement the right sender-constraint baseline?
- Is same-resource, exact-scope attenuation narrow enough for a first profile?
- Should the OAuth WG discuss DAAP at IETF 127?
Dates
-02expiry: 2027-03-03- IETF 127: 2026-11-14 through 2026-11-20, San Francisco
- BOF proposal cutoff: 2026-09-18
- WG meeting request cutoff: 2026-10-02
- IETF 127 I-D submission cutoff: 2026-11-02 23:59 UTC