RFC 8707, resource indicators for OAuth 2.0
Published in February 2020, this short extension is what stops an agent's token from being a skeleton key. It adds a resource parameter so a client says which protected resource it wants access to, letting the authorization server mint a token bound to that audience. The Model Context Protocol makes sending it mandatory.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0008
- Kind
- Standard or protocol
- Jurisdiction
- Global
- Last verified
- Added
- The document defines request parameters that let a client signal to an authorization server the identity of the protected resources it is requesting access to.
- Binding a token to a named resource is the control that makes token passthrough detectable at the receiving server.
- MCP clients must send the resource parameter in both authorization and token requests, and must send it whether or not the authorization server supports it.
- The canonical value is the resource's own URI, so the audience is a name a server can compare itself against.
Dimension by dimension
2 dimensions, each one stated, silent or open
Authorization, Limits. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- AuthorizationStated
- The token carries the name of the resource it is for, so a second resource can refuse it.RFC Editor, RFC 8707, primary source, 1 February 2020.
- LimitsStated
- Audience is a limit on reach rather than on action: it bounds where a stolen token works, not what it may do there.RFC Editor, RFC 8707, primary source, 1 February 2020.
What it changes
For a team deploying an agent
One parameter removes a whole class of lateral movement. If your agent obtains one broad token and presents it to several services, any one of those services can replay it against the others. Sending the resource indicator and validating the audience on receipt turns that into a rejected request.
Sources
What this record was verified against
- RFC Editor, RFC 8707Primary · 1 February 2020
Related
Records that sit beside this one
Model Context Protocol authorization
Global · verified 15 September 2026
Authorization servers must implement OAuth 2.1 with appropriate security measures for both confidential and public clients.
Model Context Protocol security best practices
Global · verified 15 September 2026
Token passthrough is an anti pattern where a server accepts a token from a client without validating it was issued to that server, and the document forbids it.
RFC 6749, the OAuth 2.0 authorization framework
Global · verified 15 September 2026
The framework enables a third party application to obtain limited access to an HTTP service on behalf of a resource owner, or on its own behalf.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0008 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), rfc 8707, resource indicators for oauth 2.0.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). RFC 8707, resource indicators for OAuth 2.0. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0008-rfc-8707-resource-indicators-for-oauth-2-0
- MLA
- "RFC 8707, resource indicators for OAuth 2.0." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0008-rfc-8707-resource-indicators-for-oauth-2-0.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "RFC 8707, resource indicators for OAuth 2.0." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0008-rfc-8707-resource-indicators-for-oauth-2-0.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0008-rfc-8707-resource-indicators-for-oauth-2-0
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every standard or protocol record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.