Agent Claim Ceremony

A person takes ownership of an already registered agent. The agent shows a user_code, the person approves it in a browser the agent does not control, and the agent polls until it is handed a new assertion and a wider scope. The two-channel structure is borrowed from the RFC 8628 device authorization grant.

Sequence Diagram

Click any step for details

AgentAuth ServerUser1Start the claim2Surface the code to a person3Person approves in a browser4Agent polls the token endpoint
Request
Response
Redirect
Internal

Step-by-Step Breakdown

1
Start the claim
AgentAuthorization Server
2
Surface the code to a person
AgentUser
3
Person approves in a browser
UserAuthorization Server
4
Agent polls the token endpoint
AgentAuthorization Server

Token Inspector

Specs for this flow

Sections of the protocol that normatively define this flow, plus the security considerations that apply to it.

Core specs

· The specifications that define this protocol.

Security & privacy

· Dedicated security and privacy considerations.