Agent Delegated Authorization

Consent once, scoped short-lived token, validation, and step-up for high-risk actions

Agent Delegated Authorization Consent once, scoped short-lived token, validation, and step-up for high-risk actions consent + scope issue scoped token present token validate scope + limits within limits step-up (high-risk) re-auth ok authorize payment Delegate Present + validate Step-up + authorize User · human principal · Sequence participant User human principal Auth Server · issues tokens · Sequence participant Auth Server issues tokens Agent · acts on behalf · Sequence participant Agent acts on behalf Merchant · payment provider · Sequence participant Merchant payment provider Legend request return security async trace

Delegation

  • • The human consents once and defines the scope
  • • The agent never holds raw card details or full credentials
  • • The issued token is short-lived and scoped to intent

Validation

  • • The merchant validates scope and spending limits
  • • Token checks are colored as security interactions
  • • Out-of-scope requests are rejected before any charge

Step-up

  • • High-risk actions re-authenticate the human
  • • Step-up sits outside the fast happy path
  • • Authorization returns to the agent only after checks pass