Skip to content
🔐AI Security·

AI Agent IAM: OBO Tokens & Delegation Chains

Working proof of concept for securing AI agents with their own identity: OAuth 2.0 On-Behalf-Of tokens and RFC 8693 token exchange with nested delegation chains.

Overview

Most AI agent security lives in the prompt: “don’t call this tool unless…”. That’s a hint, not a security boundary. This project moves the boundary to the API layer by giving every agent its own identity and making each downstream call carry a token the API can verify on its own: audience, scope, signature, and expiry.

When one agent hands work to another, the chain of who delegated to whom survives the hop. After the fact, you can prove which user authorized an action, which agent executed it, and how the authority was passed.

The full write-up is in Securing AI Agents in Practice.

What the Demo Does

A guest chats with a hotel assistant. Two agents act on the guest’s behalf:

  • Hotel assistant agent: books a room using the user’s On-Behalf-Of (OBO) token, obtained through an OAuth 2.0 authorization code flow with PKCE. The token records the user in sub and the agent in act.sub, and is scoped to create_bookings for the hotel API only.
  • Taxi booking agent: books an airport taxi after the room is confirmed. It exchanges the assistant’s token at a custom Security Token Service (RFC 8693) for a chained token: same user in sub, both agents nested in act, audience rebound to the taxi API, and scope narrowed to taxi_booking. The user never sees a second login.

Key Features

  • Agent identity: each agent authenticates as itself instead of sharing a service account.
  • Just-in-time authorization: sensitive actions require a user-approved, short-lived, single-audience token. No standing permissions.
  • Nested delegation chains: the act claim is nested rather than overwritten, plus a flat delegation_chain for log indexing.
  • API-side enforcement: resource servers validate signature, audience, scope, and expiry, and reject anything that doesn’t match.
  • Live audit dashboard: watch sub, act, aud, and scope change on every tool call.

Architecture

Six services, all running in Docker:

Service Role
frontend React chat app with Asgardeo login
assistant-agent LangGraph agent (Gemini) with a SecureToolNode that injects OBO tokens or triggers token exchange
backend Hotel booking API; tells user-direct bookings apart from agent-initiated ones
taxi-booking-backend Taxi API with multi-issuer JWKS, audience binding, and recursive act parsing
token-exchange-service Custom RFC 8693 STS that builds the nested delegation chain
agent-monitor Live audit dashboard of the delegation chain

Tech stack: Python, TypeScript/React, LangGraph, LangChain, Gemini, Asgardeo (identity provider), OAuth 2.0 / OIDC, JWT, Docker.

Demo Video