Rich Authorization Requests
An OAuth extension that carries structured details of the action being authorised, such as amount and payee.
Rich Authorization Requests, defined in RFC 9396, extend OAuth 2.0 with an authorization details parameter that carries structured objects describing exactly what is being authorised, such as a payment of a given amount to a given payee. Each object has a type, which lets ecosystems such as open banking define their own fields. For agents, this lets a token carry the terms of a mandate instead of a broad scope.
Agent Minute explains this term on 26 January 2027.
Related terms
OAuth scopeA value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.MandateA checkable statement of what an agent may do for a principal: which action, how much, with whom and until when.OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.