Current Datatracker draft: draft-mishra-oauth-agent-grants-01
Prepared source candidate: draft-mishra-oauth-agent-grants-02
Target: IETF OAuth Working Group (oauth@ietf.org)
Status: Active individual Internet-Draft; not IETF-endorsed and not OAuth WG-adopted
Author contacts: mishra.sanjeev@gmail.com (primary) and sanjeev@orchestrum.in (alternate)
The authoritative record is the IETF Datatracker. An individual Internet-Draft is not endorsed by the IETF and has no formal standards standing unless the working group adopts it and the standards process advances it.
The Datatracker will continue to show -01 until the -02 candidate is submitted and confirmed through the IETF submission flow.
Document
The Internet-Draft source is written in kramdown-rfc2629 format, a Markdown superset that compiles to RFC XML and from there to canonical IETF text and HTML.
The prepared revision source is at docs/ietf-draft/draft-mishra-oauth-agent-grants-02.md. The implementation report is at docs/ietf-draft/implementation-report.md.
Revision 02 Focus
- Vendor-neutral DAAP wording, with Grantex described as a reference implementation.
- Reserved example identifiers and domains instead of Grantex-specific normative examples.
- Bounded refresh-token lost-response recovery: maximum 300 seconds, same already-rotated response, no extension of the rotation chain or grant lifetime.
- Explicit
/v1/token/refresh protocol surface.
- Alignment with OAuth Security BCP, PKCE, PAR, DPoP, mTLS, and Protected Resource Metadata.
- Relationship text for OAuth identity chaining, transaction tokens, agent authorization use cases, and multi-agent collaboration drafts.
- Expanded privacy, audit-log minimization, and cross-domain correlation guidance.
Rendering Locally
If local tooling is unavailable, use the IETF Author Tools renderer.
Submitting to the Datatracker
- Render
draft-mishra-oauth-agent-grants-02.xml.
- Go to datatracker.ietf.org/submit.
- Upload
draft-mishra-oauth-agent-grants-02.xml or .txt.
- Confirm via the email link sent to the author address.
- Verify that the Datatracker page shows revision
-02.
Working Group Follow-Up
After the Datatracker accepts -02, announce it on the OAuth WG mailing list:
The main ask should be technical review of scope and overlap:
- Should DAAP remain a single profile or be split into smaller OAuth drafts?
- Which parts should align with identity chaining and transaction-token work?
- Are the proposed JWT claim names appropriate for IANA registration?
- Should the OAuth WG discuss DAAP at IETF 127?
Dates
-01 expiry: 2026-09-03
- IETF 127: 2026-11-14 through 2026-11-20, San Francisco
- BOF proposal cutoff: 2026-09-18
- WG meeting request cutoff: 2026-10-02
- IETF 127 I-D submission cutoff: 2026-11-02 23:59 UTC
Path to Standards Track
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com. Last modified on August 30, 2026