I-D Action: draft-chen-oauth-rar-agent-extensions-00.txt

internet-drafts@ietf.org Wed, 04 February 2026 02:18 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: i-d-announce@ietf.org
Delivered-To: i-d-announce@mail2.ietf.org
Received: from [10.244.6.212] (unknown [4.156.85.76]) by mail2.ietf.org (Postfix) with ESMTP id 8B397B188425 for <i-d-announce@ietf.org>; Tue, 3 Feb 2026 18:18:24 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Subject: I-D Action: draft-chen-oauth-rar-agent-extensions-00.txt
X-Test-IDTracker: no
X-IETF-IDTracker: 12.58.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <177017150415.143438.11252097295225856383@dt-datatracker-6bcfd44575-g5gjh>
Date: Tue, 03 Feb 2026 18:18:24 -0800
Message-ID-Hash: 3IDVVCX7LKAJ67J26NIVNQ7MIL3S7AJP
X-Message-ID-Hash: 3IDVVCX7LKAJ67J26NIVNQ7MIL3S7AJP
X-MailFrom: internet-drafts@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-i-d-announce.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Reply-To: internet-drafts@ietf.org
List-Id: Internet Draft Announcements only <i-d-announce.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/i-d-announce/6g_dcPILvX9UX4hbZGgulqlOQg0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i-d-announce>
List-Help: <mailto:i-d-announce-request@ietf.org?subject=help>
List-Owner: <mailto:i-d-announce-owner@ietf.org>
List-Post: <mailto:i-d-announce@ietf.org>
List-Subscribe: <mailto:i-d-announce-join@ietf.org>
List-Unsubscribe: <mailto:i-d-announce-leave@ietf.org>

Internet-Draft draft-chen-oauth-rar-agent-extensions-00.txt is now available.

   Title:   Policy and Lifecycle Extensions for OAuth Rich Authorization Requests
   Authors: Meiling Chen
            Li Su
   Name:    draft-chen-oauth-rar-agent-extensions-00.txt
   Pages:   9
   Dates:   2026-02-03

Abstract:

   OAuth 2.0 Rich Authorization Requests (RAR), as defined in RFC 9396,
   provides a mechanism for clients to request fine-grained, structured
   authorization details.  However, in emerging ecosystems of
   collaborating AI agents and long-running automated tasks, two
   critical authorization dimensions remain implicit: the required
   security assurance level of the authorization policy and the strict
   binding of authorization lifetime to a task's lifecycle.

   This document extends the "authorization_details" object of RAR by
   introducing two new members: "policy_context" and
   "lifecycle_binding".  The "policy_context" member allows a client to
   explicitly request that the authorization be evaluated and granted
   under a specific policy assurance level, mitigating policy downgrade
   attacks and enhancing user consent.  The "lifecycle_binding" member
   enables the validity of an authorization grant to be tied directly to
   the state of an external entity, such as an automated task, ensuring
   permissions are automatically and immediately revoked upon task
   completion.  These extensions provide a standardized way to achieve
   more secure, transparent, and context-aware authorization in complex,
   automated environments.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-chen-oauth-rar-agent-extensions/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-chen-oauth-rar-agent-extensions-00.html

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts