TL;DR: AI agents are already making API calls and transactions across clouds, and Strata Identity argues that OAuth 2.0, with delegation chains, token exchange, DPoP, PKCE, CAEP, and attribute-based authorization, is the most practical base for agentic identity today. The governance problem is not protocol absence but whether identity controls can operate at machine speed without losing traceability, revocation, or policy context.
Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “OAuth and Agentic Identity: The Foundation for Zero Trust AI—and What’s Next”.
Key questions
Q: What breaks when OAuth scopes are used to authorise agent tool calls?
A: OAuth scopes break down when they are asked to authorise a specific agent action, because scopes do not fully express who is acting, what tool is being called, with which arguments, and in what context.
Q: Why do AI agents need proof-of-possession tokens?
A: AI agents often operate in distributed environments where token theft is a realistic threat.
Q: How do organisations keep delegated access governable when agents act at machine speed?
A: Treat delegation as a live control problem, not a one-time grant.
Practitioner guidance
- Map agent workflows to delegation chains Inventory every AI agent flow that acts on behalf of a user, service, or another agent, and document the full token exchange path across clouds and APIs.
- Bind high-risk agent tokens to proof-of-possession Use proof-of-possession controls so intercepted tokens cannot be replayed without the private key that issued them.
- Eliminate reliance on long-lived client secrets Prefer secret-free or secret-minimised authentication patterns for AI agents operating in dynamic, distributed environments.
Bottom line: OAuth 2.0 remains the most practical base for agentic identity because it already expresses delegation, cross-domain trust, and runtime authorization patterns that AI agents need.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
OAuth is becoming the control plane for agentic identity, not because it is perfect, but because it already maps to delegated machine action. The article is directionally right to treat OAuth as the practical starting point for AI agents. What changes is that identity governance now has to preserve delegation provenance across actions, tools, and trust domains instead of merely authenticating a client once. Practitioners should treat this as a shift from application login control to runtime authority control.
A few things that frame the scale:
- A May 2025 Gartner poll of 147 CIOs and IT leaders found that 24% had already deployed AI agents, 50% were experimenting and 17% planned to deploy by the end of 2026.
A question worth separating out:
Q: When should teams prioritise CAEP over token expiration for agent access?
A: Prioritise CAEP when access needs to change mid-task, when agents cross trust boundaries, or when risk conditions can shift faster than token lifetimes. Token expiration is still useful, but it is a coarse control. For agentic identity, immediate policy-driven revocation is what keeps access aligned with current context.
👉 Read our full editorial: OAuth 2.0 as the foundation for agentic identity at machine speed