---
term: "Rich Authorization Requests"
category: "Mandates and authorisation"
url: https://agenticopenfinance.com/glossary/rich-authorization-request
source: AgenticOpenFinance glossary
---

# Rich Authorization Requests

> An OAuth extension that carries structured details of the action being authorised, such as amount and payee.

Rich Authorization Requests, defined in RFC 9396, extend OAuth 2.0 with an authorization details parameter that carries structured objects describing exactly what is being authorised, such as a payment of a given amount to a given payee. Each object has a type, which lets ecosystems such as open banking define their own fields. For agents, this lets a token carry the terms of a mandate instead of a broad scope.

Related terms: [OAuth scope](https://agenticopenfinance.com/glossary/oauth-scope.md), [Mandate](https://agenticopenfinance.com/glossary/mandate.md), [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md), [Access token](https://agenticopenfinance.com/glossary/access-token.md)
