Mandates and authorisation

Token exchange

An OAuth protocol for swapping one security token for another, recording when one party acts on behalf of another.

OAuth 2.0 Token Exchange, defined in RFC 8693, lets a client present one security token to an authorisation server and receive another, for example a narrower token for a downstream service. It distinguishes impersonation, where the new token simply represents the subject, from delegation, where the token identifies both the subject and the actor acting on the subject's behalf. Delegation with an actor claim is how an agent's identity can travel alongside the user's through a chain of calls.

Agent Minute explains this term on 9 February 2027.

Related terms