Skip to content

docs: add RFC 8693 token exchange research note - #61

Merged
rkoster merged 5 commits into
mainfrom
research/rfc-8693-token-exchange
Sep 22, 2026
Merged

rkoster merged 5 commits into
mainfrom
research/rfc-8693-token-exchange

Conversation

@rkoster

@rkoster rkoster commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

What is this note about?

A companion research note on RFC 8693 OAuth 2.0 Token Exchange. It covers the Security Token Service model, subject and actor tokens, audience/resource targeting, impersonation versus delegation, act/may_act claims, and Cloud Foundry mappings to UAA, instance identity, service bindings, gateways, and audit.

This is a separate PR from the RFC 9943 SCITT note.

Checklist

  • My note lives in research/ and uses a lowercase kebab-case filename.
  • It starts from research/TEMPLATE.md and has valid frontmatter.
  • It has the four required sections.
  • I added relevant tags.
  • Sources are linked.
  • It's on-topic for agentic workloads on Cloud Foundry.

wayneeseguin
wayneeseguin previously approved these changes Sep 22, 2026

@wayneeseguin wayneeseguin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's merge it.

@rkoster
rkoster merged commit 596e410 into main Sep 22, 2026
1 check failed
@rkoster
rkoster deleted the research/rfc-8693-token-exchange branch September 22, 2026 07:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants