Skip to content

OAuth 2.0 Token Exchange.

OAuth 2.0 Token Exchange (RFC 8693) lets a client trade one security token, such as a user's ID token or access token, for a new token with a different audience, scope, or holder at an authorization server.

Token Exchange is the general-purpose adapter of OAuth. Any time a token is right for one hop but wrong for the next, Token Exchange converts it at the authorization server instead of passing the original along. Forwarding a user's token unchanged to another service is token passthrough, and the MCP authorization specification forbids it for exactly this reason.

For AI agents, the delegation semantics matter most. An agent acting for a user should hold a token that names both of them. That gives you narrow scopes per task and an audit trail showing which agent identity acted for which person. The token management for AI agents guide covers lifetimes and storage.

Token Exchange is also a building block for newer patterns. The ID-JAG draft uses it to get an identity assertion from an enterprise IdP, then uses the RFC 7523 JWT bearer grant to turn that assertion into an access token.

Common questions

What is OAuth 2.0 Token Exchange?

It is the RFC 8693 grant that lets a client present one token at an authorization server and receive a different one. It is used to narrow a token's audience or scope, to cross trust domains, and to let an agent or service act on a user's behalf.

What is the difference between subject_token and actor_token?

The subject_token identifies who the new token is about, usually the user. The actor_token identifies who is acting, such as an AI agent or backend service. When both are present, the issued token can record the actor in an act claim.

What is the difference between delegation and impersonation?

With impersonation the new token represents only the subject, so downstream APIs see the user and nothing else. With delegation the token names both the subject and the actor through the act claim. For AI agents, delegation keeps an audit trail of which agent acted for which user.

How does ID-JAG use Token Exchange?

In the ID-JAG flow, the requesting app sends the user's ID token or SAML assertion to the enterprise IdP as an RFC 8693 subject_token and asks for the token type urn:ietf:params:oauth:token-type:id-jag. The IdP returns an ID-JAG only if admin policy allows the target audience.

Related terms

In the guides

Last updated 2026-10-05.