[OAUTH-WG] Re: Feedback and questions to Identity Assertion JWT Authorization Grant

Karl McGuinness <me@karlmcguinness.com> Sun, 26 July 2026 04:41 UTC

Return-Path: <me@karlmcguinness.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 75F4511EB995A for <oauth@mail2.ietf.org>; Sat, 25 Jul 2026 21:41:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785040883; bh=RlmOK2eAl7n1mHKcNw0jYV8dVXMOKJyDqXhacZyUAZ0=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=Anh9S28qCe9pCXg1UINuuCuBjo7PkbwL7VflMqX/+3TBAyiEMwABS/ivz1XyuUpNb bWCmA1qvVlBXSGGwFjYTmVmaUcf+TsbKWKj3loonN7Qgb59oVhT8ns3PBMWO3mogwn VRYeyXy6daTkjZjSKxS+Qs1bjRue3dxMjVaYlPck=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.006
X-Spam-Level:
X-Spam-Status: No, score=-1.006 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTML_OBFUSCATE_10_20=0.093, MANY_SPAN_IN_TEXT=1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=karlmcguinness.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wSBag5IdtSVI for <oauth@mail2.ietf.org>; Sat, 25 Jul 2026 21:41:22 -0700 (PDT)
Received: from mail-wm1-x32a.google.com (mail-wm1-x32a.google.com [IPv6:2a00:1450:4864:20::32a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5B6CD11EB9955 for <oauth@ietf.org>; Sat, 25 Jul 2026 21:41:22 -0700 (PDT)
Received: by mail-wm1-x32a.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso15845995e9.3 for <oauth@ietf.org>; Sat, 25 Jul 2026 21:41:22 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785040875; cv=none; d=google.com; s=arc-20260327; b=UgpPg3Q/nKaRiENcpC3Vaitosh7B/v/rGPrSCIX0h3BMvYqatLyzI41QqsClFEUxwx W98ht83pptdhhdxN0Ae3M37xmPoaMXq5pEfyIfmIP5soqcFEzalDONMvdX9DNvsi+/AZ ylRm08XGh0LCR82ci1KLGqdVn5/yYzp2WKm/7MLzoBLwKKD2u6FlIM7QFcJ6xGSsYaG2 zv5b2jZFIk+vNQwIlKESyv3r63X3mn6hngx+RqhpL5Dy0OnfzJIkCHP+EFaEz/shJUq5 mqDfLWbU/IXqZbkiyJA2BOF/ep6r0i0AtFGonl5s2/xQSajCPFG5Szg+Oisc5a8t2mCe BksA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=RlmOK2eAl7n1mHKcNw0jYV8dVXMOKJyDqXhacZyUAZ0=; fh=K0sCKf21B4FV7xELqRgqOy+1MiLDISxpnHqd+3m6ZSQ=; b=qIoxRxiw1qB05DwqOCUUbwEL1nzbBkhTS+VTRwjVvz5NHL22eCtOdqaL+K4M9x4PmR hlUG/tpFB3XcazgV0uHg80A5WtJIudiqaIMjTvBzmjH1JGL9E5uriKd3X4Mgyxm2LC22 CIHDc61WoBwLyVQ1M9K91rz8Av9/OSi66MFjIO365I3wIGY/bOf4Uw2nPOvHK+8SMgvd ihObZR4LrrWSnCfAN1/fiaxnxo6U/Yv02FR/J0tZNdb7rA8KpLzwpU/rxbjAEybZu6G+ 62BES/Ep2rnW0zZgtRANlQDUiqrCZnidx3rNr//RYoFZMdlPX2UIZlv8Q69IFieBIPeD CMSg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=karlmcguinness.com; s=google; t=1785040875; x=1785645675; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=RlmOK2eAl7n1mHKcNw0jYV8dVXMOKJyDqXhacZyUAZ0=; b=HieXr8SOi2/sh8Q1RIeHvEzEfs8yZ2AfJnTn+hck9S5q1SE5ilPF0x69+JKqXwHNZ2 tC3Co4qEkd/6ZKto72Z9JdonxdtQ0CtaA9tLIlYJA5x7nBMKXxlZeJca1XVQc6JGwh4Q fIQhxoLlxNwOIPUvZ8GX3gbFyNRR0djkGUP4a0yEqL4kVpW8ENZnO1OlmyYaC1aSZW5u GisCgzLSmpHS79u8ZHzI6Pi6lFLmS0jJ/pGEFwA2M7JZEkOeuAGtEEyaTS2TjNKd2TXg RR43KBKI5blqAPtzac9qk6kjCBvz5EMC4C33pilZ9Ex7GleK8wYWVcM0L2NInAgYp7i6 ECjA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785040875; x=1785645675; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=RlmOK2eAl7n1mHKcNw0jYV8dVXMOKJyDqXhacZyUAZ0=; b=o1eLA8Z4/+mWezFzeScg+fbSmq/mz/yp8PM6S3beNmd3kKr7ij8vaBTGr2IvTgzqf5 UHMjeqVadhhavY2j6GIsJZM2qhHdmyMR94BqoYkce6J0CZYCC5xewevTkBGgDSHkY1dD Htu4Bg57Q/nSXQ6r1yoYfyttjJ7w4Q3v4oqug0nNGKDwaZR6qB6qfvTGao4zj6PvEklL rcchM8e7FUntTg0H7vSYg0OqpB3363WFS1tMnEqj7fljWrRa6Ii6M+h8wE5CqIiPLq1Q EAz+jRWNiRWXIQ47ElDKlr8YufKi5XaaTWMUfL5+dvRMR2rsglXsAihGg9qBT+bYW7cc DUww==
X-Forwarded-Encrypted: i=1; AHgh+RrDgSAhnaDe0HE1EaOgRdUVr69Gp00ZeGYidtXlU2Ec03L8nXlVVuBBTlWszrLWxfAUlPX0XQ==@ietf.org
X-Gm-Message-State: AOJu0YzwHAhnLu6/MPRdhxMiKuGkroWcdVq0w1RIH1v56nsHGcTt6Fbp WYf8tho06Fd1LBtJbUh2DxTx0TPOvFzYrAPPeXkqmMgr1kr5koKqkJMXakSwbtKP/ayxeS+lJfI DShWNQcSCQKB11eL5It2D7cIsiPHLLJXp/1jzCSAJ/w==
X-Gm-Gg: AR+sD10ht1kYPQyUqu6Zn5dq+1Yu6fJtYLzgFnV8onr2ppDBdJkA8H9v4Z2RjU7YA5+ UbGQPUEb18Eepb1vqVHUBqeWh5cjpEOJoyEEgbezTqWfRRcU7C82KQcA2rP2lUF7LpCMGy7xCoP ljggUZ191POctPxMCgt/P73Dbtkq4lWtOK88mhzkfjlLuVXAhxazXvO8lgKiT+tkTRNmJUqvjnv NMoWUSIFD8rNORAYbDpsphXLkglwyJ9/TTnGmFMbrDBmKr3joO0V4pVDOuBViassahEgImQninM s0qrFK0m44WimhSiVB4P6vc39GL/72Mx48DnnYiK1qvVWPGzkRw6yXZaYEi7SlHSkrxz6AnTzqY OK3Es0lowva9faOksINen9GoxGtM=
X-Received: by 2002:a05:600c:4eca:b0:493:c42e:5be0 with SMTP id 5b1f17b1804b1-496b563fd7emr55258985e9.0.1785040874048; Sat, 25 Jul 2026 21:41:14 -0700 (PDT)
MIME-Version: 1.0
References: <VI0PR04MB118413323792DAE4ADD64D1B193C12@VI0PR04MB11841.eurprd04.prod.outlook.com> <CAPVrLW0EfCwhFV_e-NwcNS5wSe_G9tH1ju2wdOh7ovvmfFo06Q@mail.gmail.com> <VI0PR04MB11841984AA19F3B4CD8E97F0F93C02@VI0PR04MB11841.eurprd04.prod.outlook.com>
In-Reply-To: <VI0PR04MB11841984AA19F3B4CD8E97F0F93C02@VI0PR04MB11841.eurprd04.prod.outlook.com>
From: Karl McGuinness <me@karlmcguinness.com>
Date: Sat, 25 Jul 2026 21:41:02 -0700
X-Gm-Features: AUfX_myYdbScDMB_ceWdmT11cL1UnA4gImJauEpWcG-o5KByBqmXXJiNBZ1w0fs
Message-ID: <CAPVrLW0Jtk=7ZJ-4er4T0i_2znXt7g+c306AWZcGtj1v9OgqAg@mail.gmail.com>
To: Yaron ZEHAVI <yaron.zehavi@rbinternational.com>
Content-Type: multipart/alternative; boundary="000000000000351a9506577c3751"
Message-ID-Hash: TQJG5BR3LDZC6QA33BCBMB3RYW4VXTIJ
X-Message-ID-Hash: TQJG5BR3LDZC6QA33BCBMB3RYW4VXTIJ
X-MailFrom: me@karlmcguinness.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "public@karlmcguinness.com" <public@karlmcguinness.com>, oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: Feedback and questions to Identity Assertion JWT Authorization Grant
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/AwhnAkRWz5gBgtbalEBkrPkpErY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Yaron,

Thanks for the detailed walkthrough. Responses on the two parts.

*Input tokens.* Filed #115
<https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/115>
 with the rationale in detail. An access token may contain identity claims,
but it is not an identity assertion for the client. Its primary contract is
authorization to a resource. OIDC introduced the ID Token because OAuth
access tokens were intentionally not suitable as a portable authentication
artifact. Similar questions have come up across several ID-JAG, XAA, and
MCP Enterprise-Managed Authorization threads. Would appreciate your view on
#115
<https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/115>
 so we can consolidate the discussion in one place rather than in parallel.

On draft-gerber-oauth-deferred-token-response
<https://datatracker.ietf.org/doc/draft-gerber-oauth-deferred-token-response/>
 and refresh token rotation: haven't dug into issue #10 yet. Will follow up
there rather than in this thread.

*RAR in ID-JAG.* Your walkthrough matches how I'd expect an IdP product to
operationalize this. Your draft is where the productization scaffolding
lives. Reference architectures and best practices are the layer that
operationalizes it across deployments. Governance policies attached to
imported RAR type schemas is directly analogous to how IdPs today import
role and entitlement definitions via SCIM and then apply governance to
their issuance during JIT access, access request and approval workflows,
and provisioning processes. Same shape, different artifact.

Related: I've added support for draft-zehavi-oauth-rar-metadata in the
editor's draft of draft-mcguinness-token-xchg-target-svc-disco
<https://mcguinness.github.io/draft-mcguinness-token-xchg-target-svc-disco/draft-mcguinness-token-xchg-target-svc-disco.html>
 (OAuth 2.0 Token Exchange Target Service Discovery). It can act as an
IdP-side catalog for XAA, similar to SSO dashboards in IdPs today. Your
draft describes authorization detail types server-wide, this one reports
per-subject Token Exchange Target eligibility. Would appreciate your
feedback before the next version is published.

For JIT specifically, draft-mcguinness-oauth-insufficient-claims
<https://datatracker.ietf.org/doc/draft-mcguinness-oauth-insufficient-claims/>
 and ID-JAG issue #83
<https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/83>
 propose an insufficient_identity_claims error and required_claims negotiation
to close the interop gap between what a RAS needs for account resolution
and what the IdP-issued ID-JAG carries. Would appreciate your feedback on
#83
<https://github.com/oauth-wg/oauth-identity-assertion-authz-grant/issues/83>.
There's likely alignment worth exploring with your RAR metadata approach.

Between your draft-zehavi-oauth-rar-metadata
<https://datatracker.ietf.org/doc/draft-zehavi-oauth-rar-metadata/>,
draft-gerber-oauth-deferred-token-response
<https://datatracker.ietf.org/doc/draft-gerber-oauth-deferred-token-response/>
, draft-parecki-oauth-jwt-grant-interaction-response
<https://datatracker.ietf.org/doc/draft-parecki-oauth-jwt-grant-interaction-response/>,
and draft-rosomakho-oauth-txn-challenge
<https://datatracker.ietf.org/doc/draft-rosomakho-oauth-txn-challenge/>,
there's a rich substrate that composes with ID-JAG for discovery,
challenge, and approval / remediation flows around fine-grained access and
governance. I haven't seen anything in your walkthrough that requires
changes in the ID-JAG spec itself. The composition seems to work on top of
what's already there. Let me know if I missed anything, and feel free to
open GH issues for any gaps you identify that would touch invariants in the
spec.

Thanks again for the write-up.

-Karl

>