A full featured, secure, standards compliant TypeScript implementation of an OAuth/OIDC authorization server for Nodejs that utilizes JWT and Proof Key for Code Exchange (PKCE)
-
Updated
Sep 2, 2026 - TypeScript
A full featured, secure, standards compliant TypeScript implementation of an OAuth/OIDC authorization server for Nodejs that utilizes JWT and Proof Key for Code Exchange (PKCE)
Highflame ZeroID: Autonomous Agent Identity Management System (AAIMS)
OAuth 2.0 Token Exchange delegated implementation with Microsoft Entra ID and OpenIddict (RFC 8693)
An implementation of RFC 8693 for Ory Hydra, providing powerful capabilities for token exchange in OAuth 2.0 and OpenID Connect servers.
Demo system for Keycloak OAuth2 Token Exchange
Reliable and explainable consultation between LLM agents: attenuating capability grants with an RFC 8693-style actor chain, typed disagreement, announced degradation, and a contestable append-only record.
Capability passports for MCP agents — delegated authority that can only narrow, never widen. A 2026 revival of General Magic's 1994 Telescript permit model.
Verifiable, identity-rooted delegation tokens for AI agents — built on existing standards (OIDC, OAuth 2.0 Token Exchange, JWT, NIST SP 800-63).
Interactive demo of cross-IdP OAuth 2.0 Token Exchange (RFC 8693) with Keycloak, Spring Boot, and Docker Compose.
MCP gateway with per-user identity: exchanges the caller's token (RFC 8693) so backends see the actual user, not one shared service account. Plus discovery, health checks, tracing, and fault injection.
Local sandbox showing scoped, delegated access for an AI agent with WSO2 ThunderID: RFC 8693 token exchange, the act claim, and a resource server that enforces scope.
token-visualizer
OAuth 2.0 Token Exchange (RFC 8693) demo with Spring Boot, Keycloak, and multiple frontend frameworks
Agentic token exchange: nested RFC 8693 actor chains (delegation, not impersonation) + an audience-scoped flatten governed by policy. PingFederate + PingAuthorize config-as-code, with the constraints the design didn't survive.
An AI copilot chat app that cannot exceed its user's permissions - RFC 8693 token exchange at an MCP gateway, on Kubernetes. Self-contained workshop.
Two-hour hands-on lab: build an AI agent that can't exceed its user's permissions. Six labs, from an unprotected agent to RFC 8693 token exchange on Kubernetes.
To associate your repository with the rfc8693 topic, visit your repo's landing page and select "manage topics."