Positioning note: actor chains in MCP enterprise auth (ID-JAG)
- Upstream thread: oauth-wg #73 — workload/agent identity SSO and delegated access
- Status: Open, and the ball is with us. A draft author replied on
2026-07-25 pointing the actor-chain half of the conversation at
draft-mcguinness-oauth-actor-profileand its companion receipts, proofs, and authority-bounds drafts. That move has not been answered yet. - Last verified: 2026-08-22
- Authors: Burin Labs
Unlike the other documents here there is no new proposal to file. The substance already lives in active upstream drafts, so the useful contribution is implementer feedback in those threads.
The gap#
MCP's enterprise-managed-authorization extension (the one Stable
extension in modelcontextprotocol/ext-auth) obtains
tokens via ID-JAG (RFC 8693 token exchange), but carries a single
delegated subject — no actor_token, so a nested-agent hop chain
(user → orchestrator agent → sub-agent → MCP server) collapses to one
subject and the intermediate actors vanish from the token.
Where the conversation actually is#
- ext-auth #13 — "Clarifying Agent vs User Identity" (open, stalled since 2026-01-31). The maintainer response confirms enterprise-managed-auth does not distinguish agent vs user identity and points at ID-JAG for the fix.
- oauth-wg/oauth-identity-assertion-authz-grant #73 — the
live thread (open, updated 2026-04-02): workload/agent identity SSO
and explicit delegated on-behalf-of access, reusing RFC 8693
act, explicitly enabling future actor chains. - oauth-wg #80 — optional
actor_tokenfor ID-JAG; closed completed and milestoned 2026-04-22, i.e. folded into the #73 direction rather than rejected. - MCP #214 — closed; maintainers pointed custom auth work at ext-auth. Do not reopen.
Our posture#
Adopt-not-invent (the Identity program's standing invariant): the
internal ActorChain representation
(crates/harn-vm/src/actor_chain.rs)
is already RFC 8693 act-shaped so that whatever ID-JAG ratifies is a
drop-in. Do not file a new MCP SEP or discussion for actor chains —
the venue is oauth-wg #73 (and ext-auth #13 for the MCP-specific
consequence).
What we can usefully contribute upstream, as implementer feedback on #73:
- A concrete nested-agent topology where the chain drops today (multi-hop agent delegation reaching an MCP server through enterprise-managed auth), and what the audit trail loses.
- Support for keeping nested actors audit-only (authorization from top-level claims only) — the audit-not-authz split we enforce in the reference implementation.
- A data point that scope attenuation per hop is worth representing: each hop in our chain carries the scopes it held, so narrowing is visible in the audit record.
Tracked in harn#3345 (Identity E2). Any upstream comment requires maintainer sign-off per the pro-bono filing pattern in README.md.