<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mission-Bound OAuth on Control Plane by Karl McGuinness</title><link>https://notes.karlmcguinness.com/tags/mission-bound-oauth/</link><description>Recent content in Mission-Bound OAuth on Control Plane by Karl McGuinness</description><generator>Hugo</generator><language>en-us</language><managingEditor>public@karlmcguinness.com (Karl McGuinness)</managingEditor><webMaster>public@karlmcguinness.com (Karl McGuinness)</webMaster><lastBuildDate>Fri, 22 May 2026 14:00:00 -0700</lastBuildDate><atom:link href="https://notes.karlmcguinness.com/tags/mission-bound-oauth/index.xml" rel="self" type="application/rss+xml"/><item><title>Mission-Bound OAuth Minimum Profile: Intent-Based Authorization Without a New Protocol</title><link>https://notes.karlmcguinness.com/notes/mission-bound-oauth-minimum-profile/</link><pubDate>Fri, 22 May 2026 14:00:00 -0700</pubDate><author>public@karlmcguinness.com (Karl McGuinness)</author><guid>https://notes.karlmcguinness.com/notes/mission-bound-oauth-minimum-profile/</guid><description>Agent workflows expose a missing OAuth layer: durable task authority. The Minimum Profile adds five concrete protocol surfaces: a mission_intent RAR envelope, a resource_access RAR type, a Mission record at the AS, a mission claim on access tokens, and Mission-state enforcement across derivation. Everything else composes with existing OAuth, RAR, PAR, Token Exchange, ID-JAG, AuthZEN escalation, and shared signals.</description></item></channel></rss>