Token exchange
An OAuth protocol for swapping one security token for another, recording when one party acts on behalf of another.
OAuth 2.0 Token Exchange, defined in RFC 8693, lets a client present one security token to an authorisation server and receive another, for example a narrower token for a downstream service. It distinguishes impersonation, where the new token simply represents the subject, from delegation, where the token identifies both the subject and the actor acting on the subject's behalf. Delegation with an actor claim is how an agent's identity can travel alongside the user's through a chain of calls.
Agent Minute explains this term on 9 February 2027.
Related terms
Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.Multi-agent systemSeveral agents that divide a task between them and exchange work through a protocol.PrincipalThe person or organisation on whose behalf an agent acts and whose authority the agent exercises.Know Your Agent (KYA)Checking which agent is acting, who operates it and whom it acts for, before letting it act.