FLASHY ID DELEGATED AUTHORITY PROFILEv0.3DRAFT2026-08-19editor: Flashy Group
Delegated authority across organizational boundaries
The wire format is standards-based and interoperable. The organizational semantics above it are ours. A proprietary format would make cross-organization verification impossible, which is the entire product — so there is no proprietary format.
A compact JWS. The delegation chain travels in del, ordered root-first. Every link carries its own expiry; the effective expiry is the minimum across the chain.
Scopes are additive and never redefined. A scope’s meaning is fixed at registration; a narrowing change requires a new scope, not an edit. Registration is by pull request against this document, reviewed by the editor. Vendor-prefixed scopes (x-) are never verified across a boundary.
proposal.draftCompose a proposal. Commits the organization to nothing.Registered
payment.executeMove funds within the grant’s spend limit. Requires lim.spend_max.Registered
contract.signBind the organization. Reserved and unissued — agents propose, a named human signs.Reserved
identity.delegateMint a child grant. Attenuation is checked at issue time, not at use.Registered
data.readRead a named resource. Resource pattern travels in the grant, not the scope.Registered
x-*Vendor namespace. Never verified across an organizational boundary.Non-portable
The governed registry, with requirements and key history, lives at /registry/scopes.
RFC 7515 (JWS), RFC 7517 (JWK), RFC 7519 (JWT) and RFC 8725 best practices. EdDSA (Ed25519) required; alg is never read from the header without a key match.
Tracks
OAuth 2.0 Token Exchange (RFC 8693) delegation semantics, and the emerging work on agent authorization in the IETF OAuth working group. Where that work lands on a chain representation, this profile will follow it and deprecate del.
Deliberately extends
Nothing in the existing specifications carries an ordered chain of principals with per-link attenuation and a revocation pointer. del, lim and cnf.contract_authority are ours. They are additive claims a conforming JWT verifier ignores safely.
Every refusal is named on the wire. A verifier that returns a boolean has thrown away the only information the caller needed — which of these it was, and therefore whether to retry, escalate to a human, or stop.
reasonMeaningRetry
chain_widenedA grant claims more scope, resource, or a looser limit than its parent. The whole chain fails, not the offending link.never
broken_chainA link’s issuer is not the holder of the link above it — the chain does not connect.never
expiredA link is past its expiry at the evaluated time. The effective expiry is the minimum across the chain.never
revokedA link (or one above it) has been withdrawn. The reason carries which link, so a rotated agent reads differently from a withdrawn human.never
out_of_mandateThe chain is valid and the requested action exceeds it — a missing scope, a resource outside the grant, or an amount over the limit.escalate
scope_unmappedA charter capability maps to no registered scope. Refused rather than guessed at grant issue time.never
empty_chainThere is no delegation to evaluate — the assertion carried no chain.never
Every version, dated, with what changed on the wire. A verifier written against any listed version still returns the same answer for an assertion of that version.
v0.32026-08-19Draft · current
Made del ordering normative (root-first, previously unspecified) and split the refusal reasons into the coded vocabulary above. The reference kernel (src/grants) and verify SDK (src/sdk) now implement this profile. Assertions signed under v0.2 continue to verify unchanged.
v0.22026-07-14Superseded
Added lim for spend and approval thresholds. Verifiers were required to check it; issuers were not yet required to enforce it, and that asymmetry is still open.
v0.12026-06-02Superseded
First public draft. iss, sub, act, del, scp, exp, jti over EdDSA. No limits, no constraints, no refusal vocabulary.
Roadmap APIs live here with a version marker, never in the docs.
v0.4 · Q4 2026Agent as an addressable entity. Today agentName is a string; the profile assumes a resolvable principal that does not yet exist in source.
v0.4 · Q4 2026lim semantics enforced server-side. Currently advisory — a verifier checks them, the issuer does not enforce them.
v0.5 · Q1 2027Policy claim. Server-side evaluation of organizational rules; today an agent supplies its own impact and LOW auto-approves.
v0.5 · Q1 2027Revocation propagation to cached assertions. Push, status list, or short expiry — the choice is open and the argument is on the mailing list.