Skip to main content
OAuth3 artwork — image 1 of 2 OAuth3 artwork — image 2 of 2

OAuth3: Mfano wa Ujumbe wa Wakala Uliopendekezwa

A proposed standard for AI agent delegation. Scoped permissions, instant revocation, full audit trails.

Status:Mpango wa rasimu wa pendekezo la Phuc Labs. Haukuidhinishwa na IETF, W3C, au shirika lolote la viwango.

OAuth3 ni nini?

OAuth 2.0 was built for delegated authorization between apps. OAuth3 extends this to AI agents.

[PH0]] ni pendekezo la utume wa kiwango cha umri wa AI. It addresses four critical problems:

Jinsi OAuth3 Inavyofanya Kazi

1
Wewe unaombaMsaidizi wa kumsaidia mtu kufanya kazi fulani
2
Mfanyakazi wa Agents atangazaNi ruhusa gani hasa inahitaji
3
Wewe kuchunguza & kupitishaau kukataa kila ruhusa
4
Mfanyakazi hufanya kaziNdani ya kiwango cha kupitishwa tu
5
Unaweza kufutaUfikiaji wa papo hapo, wakati wowote

Nguzo Nne za Nguzo

Scopes Granular

Si kupata barua pepe zote lakini kusoma barua pepe kutoka kwa bosi, kamwe kufuta yoyote.Ruhusa ni maalum.

Utoaji wa Ruhusa ya wazi

Unaona kile ambacho wakala anataka, unakubali au kukataa, hakuna ruhusa za kimya, hakuna ufikiaji wa ghafla.

Uondoaji wa papo hapo

Acha kumwamini wakala? acha kupata mara moja. Tokeni hufa mara moja. Hakuna kusubiri kwa ajili ya mabadiliko ya password.

Njia kamili ya Ukaguzi wa Ukaguzi

[PH0]] imeundwa kusaidia saini, wakati stempu ya vitendo rekodi. Angalia kila hatua wakala alichukua, wakati alichukua, na kwa nini. Architected kwa FDA Sehemu 11 kufuata (mteja uthibitisho required kwa ajili ya vyeti kamili).

OAuth3 Matters Why

Matatizo yaliyopo: Today, you either give an agent full access or no access at all.

Suluhisho la OAuth3: An OAuth3 token contains three things: scope, TTL, and evidence requirements.

Aikin OAuth3 Token

Notice: the agent can READ inbox but not SEND. It can DRAFT replies but not DELIVER. Every action is logged.

{ "identity": "agent:gmail-triage:v1", "scopes": ["gmail.read.inbox", "gmail.modify.labels"], "expires": "2026-03-27T15:00:00Z", "revocation_ref": "srv_rev_123", // server-side only "signature": "sha256:8f3c..." }

Notice: the agent can READ inbox but not SEND.

Tayari kupeleka kwa usalama?

Ready to delegate safely?

Muhtasari wa umma:Karatasi ya OAuth3• Chanzo cha spec:alama ya alama ya ndani ya eneo