Skip to content
Agent Identity

IETF · 21 May 2026

Transaction Tokens For Agents

draft-araut-oauth-transaction-tokens-for-agents-02

Individual draftDraft — expect changeIdentity + Authn + AuthzAgent-specificField guide

Helps when you already run Txn-Tokens internally and the caller is now an LLM agent instead of a microservice.

At a glance

Problem
Apply the Transaction Token model to agent call chains so task context stays immutable as agents invoke tools and other agents inside a trust domain.
Identity / authn / authz
Context propagation of identity and authorization purpose, not a user login protocol.

Actors

  • Agent workloads
  • Transaction Token Service
  • Tools

01

The gap for agents

Apply the Transaction Token model to agent call chains so task context stays immutable as agents invoke tools and other agents inside a trust domain. Helps when you already run Txn-Tokens internally and the caller is now an LLM agent instead of a microservice.

02

Actors and trust boundaries

Same as the WG transaction-tokens draft. The WG document is the one that will likely become the RFC; this is a usage profile.

03

Mechanics

draft-araut-oauth-transaction-tokens-for-agents-02, 21 May 2026. Same TTS issuance as the WG draft, with agent-specific guidance for purpose and context fields.

tctx / purpfrom spec
Quoted reuse: immutable task context and purpose.

04

Step-by-step flows

Flow 1

Agent entry issues a Txn-Token

  1. 1

    Agent authenticates as a workload and, if needed, as a user delegate.

  2. 2

    Requests a Txn-Token with agent-appropriate purpose/context.

  3. 3

    Tool calls inside the domain carry the Txn-Token. tctx stays immutable.

05

Identity vs authentication vs authorization

Context propagation of identity and authorization purpose, not a user login protocol.

06

How it composes

07

What bites agent implementers

  • Implementing the profile instead of the WG draft

    When they disagree, the WG document wins.

08

Stability — what you can ship

Individual draft-02, 21 May 2026. https://datatracker.ietf.org/doc/search/?name=transaction-tokens-for-agents

Catalog claims (short form)

tctx / purp
Immutable task context and purpose.

Implementer notes

Individual draft. The WG document is the one that will likely become the RFC; this is a usage profile.

Relationship to others

Primary sources

  • Datatracker searchhttps://datatracker.ietf.org/doc/search/?name=transaction-tokens-for-agents