Flow 1
Entry workload issues a Txn-Token
- 1
External request authenticated (OAuth user token, mTLS, …).
- 2
Entry workload requests a Txn-Token from the TTS with purpose and context.
- 3
Downstream calls carry Txn-Token plus workload authn (WIT+WPT or mTLS).
- 4
Each hop verifies both. tctx stays immutable. Workloads may replace the token per the draft's rules but must not widen authority.