Scoped credential
A credential limited to specific actions, resources, audiences or time, so a leaked or misused copy can do far less than its holder's full authority.
A scoped credential is a credential that authorizes only specific actions on specific resources, usually for a named audience and a limited time, instead of everything its holder is allowed to do.
Ways to narrow a credential. OAuth 2.0 and its extensions provide most of the building blocks:
| Limit | Mechanism |
|---|---|
| Actions | scope strings defined by the authorization server (RFC 6749, section 3.3) |
| Fine-grained detail | authorization_details objects with a type plus fields such as actions, locations and identifier (RFC 9396) |
| Audience | Resource indicators that name the service the token is for (RFC 8707) |
| Holder | Sender-constrained tokens, bound to a client certificate (RFC 8705) or a DPoP key (RFC 9449) |
| Time | The token’s lifetime, such as expires_in (RFC 6749) |
Scope strings are coarse. orders:write says nothing about which order or how much. RFC 9396 lets a client ask for structured permissions instead. Illustrative, following the RFC’s structure:
[
{
"type": "order_refund",
"actions": ["refund"],
"locations": ["https://api.shop.example/orders"],
"identifier": "order-1042"
}
]
In A2A. Servers declare OAuth 2.0 and other schemes in the Agent Card. The A2A enterprise guidance suggests using OAuth scopes so that a client can invoke some skills and not others. For credentials passed along a chain of agents, the specification recommends binding each one to the agent that requested it, so no other agent in the chain can use it. It does not define the scope or format of credentials obtained through TASK_STATE_AUTH_REQUIRED.
Why it matters for agents. OWASP’s Excessive Agency entry lists excessive permissions as a root cause of damaging agent actions, and prompt injection as one trigger. A token that can refund one order, and nothing else, caps what a manipulated agent can do with it.
Neighbouring terms. A mandate is a scoped credential that also records the principal’s approval. Credential revocation ends a credential before it expires.
Sources
- RFC 6749: The OAuth 2.0 Authorization Framework, section 3.3: Access Token Scope (accessed )
- RFC 9396: OAuth 2.0 Rich Authorization Requests (accessed )
- RFC 8707: Resource Indicators for OAuth 2.0 (accessed )
- RFC 8705: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens (accessed )
- RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP) (accessed )
- A2A documentation: Enterprise Implementation of A2A (accessed )
- A2A Protocol Specification, section 7.6: In-Task Authorization (accessed )
- OWASP Top 10 for LLM Applications 2025: LLM06 Excessive Agency (accessed )