3 ms·
As I am working on an internal platform for AI agents right now, this is of high interest to me. The way my design attempts to approach the problem is using OAu
by 9dev 7mo ago
As I am working on an internal platform for AI agents right now, this is of high interest to me. The way my design attempts to approach the problem is using OAuth access tokens with granular permission scopes, and the token exchange grant: When a user triggers an agent, the chat application will take the user's access token and its own, and exchanges both for a new token that includes the original subject claims for agent and user, and the granted scopes. It then requests an agent run using the new token; if the agent worker needs to make requests on its own (to MCP servers or tools), it follows that same process to exchange its own token and the request token for a job token. That way, all requests made on behalf of a user have a fully cryptographically verified audit trail, including the permissions granted.
It feels like that doesn't cover all things outlined in this framework, especially the hardware attestations and public verifiability, but I think it's a solid start.