AAuth

5 Articles

The Convergence and the Wagers

The Outside Evidence, the Named Bets, and the Handbook's Close

Series Weighing Mission-Bound Authorization Part 3 of 3

The handbook closes on judgment. First the strongest outside evidence: AAuth, the proposed clean-slate agent protocol, adopted a first-class mission layer in its 01 revision after this model’s AAuth mapping circulated: not independent replication, adoption by a designer free to say no, which is its own kind of proof. Then the honest bets: admission grain, issuer home, the price of Termination, the necessity of the object itself, the portability of its authority, and the classification line, each stated with the evidence that would falsify it. The laws and the claim gate are the invariants. The bets are the wagers, and deployment experience, not this handbook, will settle them.

OAuth AAuth Authorization Agentic Identity Mission-Bound Authorization Internet-Draft

A Blocked Agent Is a Captive Client

Long-running agents discover mid-task that they need a destination their egress proxy does not allow, and the block comes back as an opaque connection failure with no machine-actionable way to ask for access and no human standing by. That block is a requestable denial, and the egress proxy is a policy enforcement point. RFC 8908, the Captive Portal API, supplies the recovery state machine for a blocked client on a network: discover captivity, learn the remediation endpoint, and retry after policy changes. A headless agent can use that state machine, with the denial carried by Proxy-Status and Problem Details where an HTTP response exists and by an authenticated side-channel status API where it does not. The recovery can ride the captive portal at two altitudes, destination-level on a proposed AuthZEN Access Request profile or operation-level on AAuth and Mission-bound authority. When the client already speaks AAuth, it needs no captive-portal shim at all, because AAuth carries the refusal and re-authorization in-band at the same request boundary the proxy already enforces.

Agentic Identity Authorization AuthZEN AAuth OAuth Egress Captive Portal Delegated Authority Standards

AAuth Now Has a Mission Layer

The new version of AAuth (draft-hardt-aauth-protocol-01, since resubmitted as draft-hardt-oauth-aauth-protocol) materially changes the earlier comparison. Mission is now first-class in the protocol, with PS-mediated approval, mission-aware token choreography, and governance endpoints. The remaining gap is no longer whether Mission exists, but whether the published model is strong enough to support portable containment rather than just mission correlation and governance hooks.

AAuth Authorization Agentic Identity OAuth Mission Shaping Standards

Mission Architecture on AAuth

Series Mission-Bound OAuth Part 3 of 4

Mission-Bound OAuth argues for a durable Mission object that governs delegated authority across approval, lifecycle, delegation, and termination. This follow-up asks whether Dick Hardt’s AAuth draft is a better protocol substrate for the same model, and where AAuth still appears to need an explicit Mission-like authority object.

OAuth Authorization Agentic Identity AAuth