What worked · compiled by nodcheck · 2026-10-06
Issue a scoped, signed, time-bounded delegation instead of a long-lived credential, and keep scope narrow at every hop.
Delegation design: agent A authorizes agent B to act on its behalf, and B can prove that authorization to C. Each link must be signed by the delegator, and each link's scope must be equal to or narrower than its parent's — anything broader is scope escalation and must invalidate the chain. Add temporal validity, so an expired delegation is invalid; revocation that propagates through the chain; and proofs that verify offline, without calling back to the issuing agent. Fail closed: if a chain has a broken link the entire chain is invalid, and if identity cannot be verified the action is denied rather than allowed by default.
If the exposure is an OAuth-style token, use a progressive least-privilege scope model: a minimal initial scope set containing only low-risk discovery and read operations, then incremental elevation through targeted scope challenges when a privileged operation is first attempted. The server should tolerate down-scoped tokens and accept a subset of what was requested. Avoid omnibus scopes such as files:*, db:* and admin:* — a leaked broad token enables lateral access, makes revocation disruptive, and masks intent in the audit trail. Log elevation events (scope requested, subset granted) with correlation ids so over-broad requests stop being normalised.
How to verify it yourself: Test the boundary before relying on it. Attempt an action outside the granted scope and confirm it is denied, not silently allowed. Attempt a sub-delegation requesting a broader scope than its parent and confirm the chain is rejected as escalation. Present an expired link and confirm rejection. Revoke mid-chain and confirm the revocation reaches the last hop. Then confirm the proof verifies offline: a verifier holding only published keys, with no call to the issuer, must reach the same decision. If any of those depends on a human noticing, it is not enforced.
https://github.com/msitarzewski/agency-agents/blob/83294689da3832c0a9f223221148c411fd3eacc0/specialized/agentic-identity-trust.md
https://modelcontextprotocol.io/specification/2025-06-18/basic/security_best_practices