Skip to main content

RFC 8693, OAuth 2.0 token exchange

Published in January 2020, token exchange is the only widely deployed standard that writes down the difference between impersonation and delegation. A service can trade one token for another, and the result can record that one party is acting for another rather than pretending to be them. It is the nearest thing to an agent delegation record.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0010
Kind
Standard or protocol
Jurisdiction
Global
Last verified
Added
  • The specification defines how to request and obtain security tokens from OAuth 2.0 authorization servers, including tokens employing impersonation and delegation.
  • Delegation keeps the acting party visible in the token, while impersonation erases it, and the difference decides what a downstream log can show.
  • Token exchange is how a service holding a user's token obtains a narrower token for a downstream call, which is the shape of an agent calling a tool.
  • It was written for services rather than agents, so nothing in it bounds how many times authority may be exchanged onward.

Dimension by dimension

3 dimensions, each one stated, silent or open

Delegation, Accountability, Limits. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

DelegationStated
The exchange can record an acting party alongside the subject, so a downstream service can see that software acted for a person.RFC Editor, RFC 8693, primary source, 1 January 2020.
AccountabilityStated
Because the actor stays in the token, an audit can attribute the call to both the agent and the principal instead of only one.RFC Editor, RFC 8693, primary source, 1 January 2020.
LimitsStated
The exchanged token can be narrowed by audience and scope, but the specification does not require narrowing.RFC Editor, RFC 8693, primary source, 1 January 2020.

What it changes

For a team deploying an agent

If your agent calls downstream services with the same token it received, your logs cannot distinguish the agent from the user. Exchanging for a narrower token that names the agent as the actor costs one round trip and gives you an attributable trail, which is what every incident review will ask for.

Sources

What this record was verified against

  1. RFC Editor, RFC 8693Primary · 1 January 2020

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0010 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), rfc 8693, oauth 2.0 token exchange.
APA
GAGE (Global Academy of Generative-AI Education). (2026). RFC 8693, OAuth 2.0 token exchange. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0010-rfc-8693-oauth-2-0-token-exchange
MLA
"RFC 8693, OAuth 2.0 token exchange." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0010-rfc-8693-oauth-2-0-token-exchange.
Chicago
GAGE (Global Academy of Generative-AI Education). "RFC 8693, OAuth 2.0 token exchange." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0010-rfc-8693-oauth-2-0-token-exchange.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0010-rfc-8693-oauth-2-0-token-exchange

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every standard or protocol record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.