In the sessions, during the item "Offline workload access for user-owned resources without refresh tokens", I mentioned there's a cross-domain transaction token proposal. Sending the relevant draft to the list:
https://datatracker.ietf.org/doc/draft-liu-oauth-cross-domain-txn-token/ The draft introduces two patterns to solve cross-domain transaction tokens: * Mode A (Txn-Token I -> JAG -> Access Token -> Txn-Token II): Combines standard Identity Chaining with standard Transaction Tokens to pass workflow-related claims via JAGs and access tokens. * Mode B (Txn-Token I -> JAG -> Txn-Token II): An optimized flow allowing a downstream TTS to directly accept a JAG, reducing cross-domain round-trips for access tokens. OAuth working group is busy working on the use cases, so no solutions will be discussed this ietf, but this might be a relevant proposal to begin with. CC-ing them as well. Best, Peter
oauth_REFUa6_vHzfu-NlNe5ssDs7JPyA.eml
Description: oauth_REFUa6_vHzfu-NlNe5ssDs7JPyA.eml
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
