Delegation (agent authority)
A principal granting an agent part of its authority, so the agent can act for it within set limits while staying identifiable as the agent.
Delegation is the act of a principal granting an agent part of its authority, so the agent can act for the principal while keeping an identity of its own.
Delegation and impersonation. OAuth 2.0 Token Exchange (RFC 8693) separates the two. With impersonation, A receives B’s rights and is indistinguishable from B to anyone who receives the token. With delegation, A remains identifiable as A, and it is explicit that A is acting for B. For agents, delegation lets a business tell the customer’s agent apart from the customer, apply different limits to each, and trace which party did what.
How a token records it. RFC 8693 defines the act (actor) claim for JWTs. The top-level claims describe the subject, and act names the party currently acting. Nested act claims record a chain of delegation, with the current actor outermost. Only the current actor counts for access control; earlier actors are informational. Illustrative, following the RFC’s structure:
{
"iss": "https://issuer.example.com",
"aud": "https://orders.example.com",
"sub": "customer-4471",
"act": {"sub": "https://assistant.example.net/agents/support"},
"scope": "orders:refund"
}
In A2A. When a remote agent needs authorization partway through a task, it moves the task to TASK_STATE_AUTH_REQUIRED. A client that is itself an agent may pass the request up to its own client the same way, which forms a chain of tasks waiting on authorization. For credentials passed back down such a chain, the specification recommends binding each credential to the agent that requested it, so other agents in the chain cannot use it. It leaves the scope, representation, validity and revocation of the credential to implementations and extensions.
Delegating less. Useful delegation grants a narrow slice of authority: one action, one account, an amount cap, an expiry. A mandate and a scoped credential are two ways to write those limits into something a counterparty can check.
Neighbouring terms. The principal is the party that delegates. The confused deputy problem describes what goes wrong when a delegate’s authority is steered by someone else.
Sources
- RFC 8693: OAuth 2.0 Token Exchange (accessed )
- A2A Protocol Specification, section 7.6: In-Task Authorization (accessed )