A full featured, secure, standards compliant TypeScript implementation of an OAuth/OIDC authorization server for Nodejs that utilizes JWT and Proof Key for Code Exchange (PKCE)
-
Updated
Sep 2, 2026 - TypeScript
A full featured, secure, standards compliant TypeScript implementation of an OAuth/OIDC authorization server for Nodejs that utilizes JWT and Proof Key for Code Exchange (PKCE)
Highflame ZeroID: Autonomous Agent Identity Management System (AAIMS)
OAuth 2.0 Token Exchange delegated implementation with Microsoft Entra ID and OpenIddict (RFC 8693)
An implementation of RFC 8693 for Ory Hydra, providing powerful capabilities for token exchange in OAuth 2.0 and OpenID Connect servers.
Demo system for Keycloak OAuth2 Token Exchange
Capability passports for MCP agents — delegated authority that can only narrow, never widen. A 2026 revival of General Magic's 1994 Telescript permit model.
Reliable and explainable consultation between LLM agents: attenuating capability grants with an RFC 8693-style actor chain, typed disagreement, announced degradation, and a contestable append-only record.
Verifiable, identity-rooted delegation tokens for AI agents — built on existing standards (OIDC, OAuth 2.0 Token Exchange, JWT, NIST SP 800-63).
An AI copilot chat app that cannot exceed its user's permissions - RFC 8693 token exchange at an MCP gateway, on Kubernetes. Self-contained workshop.
MCP gateway with per-user identity: exchanges the caller's token (RFC 8693) so backends see the actual user, not one shared service account. Plus discovery, health checks, tracing, and fault injection.
Interactive demo of cross-IdP OAuth 2.0 Token Exchange (RFC 8693) with Keycloak, Spring Boot, and Docker Compose.
Local sandbox showing scoped, delegated access for an AI agent with WSO2 ThunderID: RFC 8693 token exchange, the act claim, and a resource server that enforces scope.
token-visualizer
OAuth 2.0 Token Exchange (RFC 8693) demo with Spring Boot, Keycloak, and multiple frontend frameworks
Agentic token exchange: nested RFC 8693 actor chains (delegation, not impersonation) + an audience-scoped flatten governed by policy. PingFederate + PingAuthorize config-as-code, with the constraints the design didn't survive.
Per request OAuth2 scope derivation for AI agents. Narrows an agent's standing authority down to what a single delegated request needs, using RFC 8693 token exchange against WSO2 Agent Manager and ThunderID.
To associate your repository with the rfc8693 topic, visit your repo's landing page and select "manage topics."