OAuth oauth.net

Cross-App Access

datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant

Cross-App Access (XAA), formally known as the "Identity Assertion Authorization Grant", is an extension of OAuth that enables an enterprise identity provider to manage the connection between two applications. It replaces the user's manual approval step with a token exchange to enable an application to request an access token for a resource server without any user interaction.

Cross-App Access builds on Identity and Authorization Chaining Across Domains to further profile it for interoperable implementations in an enterprise setting. In particular, it defines the claims of the ID-JAG (Identity Assertion JWT Authorization Grant) that moves across domains.

Terminology

Cross-App Access (XAA)
A pattern in which an application's access to another application's API is mediated by the IdP that both applications already trust for SSO and subject resolution. XAA extends the IdP's role from single sign-on to brokering cross-domain API access, using the same trust relationships that already exist for SSO.
Identity Assertion JWT Authorization Grant (ID-JAG)
The name of both the specification where XAA is defined and the specific JWT defined in Section 3 of that spec. The ID-JAG is the JWT issued by the IdP and presented to the Resource Authorization Server. It carries the IdP's signed assertion that the Client is authorized to access the Resource App on behalf of the user.
Client
The application that wants to access the Resource App's API on behalf of a user. The Client already has the user logged in via SSO at the IdP, and initiates XAA by requesting an ID-JAG from the IdP.
Resource App
The application whose API the Client wants to access. Both the Client and the Resource App trust the same IdP for SSO. The Resource App delegates authorization decisions to its Resource Authorization Server.
Resource Authorization Server
The OAuth authorization server operated by the Resource App. It receives the ID-JAG from the Client, validates it against the IdP's signing keys, and — if authorized — issues an access token the Client can use to call the Resource Server.
Resource Server
The API of the Resource App. It accepts and validates access tokens issued by the Resource Authorization Server.
Token Exchange (RFC 8693)
An OAuth 2.0 extension for exchanging one token for a different token. In XAA, the Client uses Token Exchange to exchange the user's existing SSO session (an OIDC ID token, refresh token, or SAML assertion) with the IdP for an ID-JAG.
Authorization Grant
The abstract concept defined in RFC 6749 representing a user's authorization for a client to access a resource. In XAA, the ID-JAG is the authorization grant — it is what the Client presents to the Resource Authorization Server to obtain an access token.
JWT Authorization Grant (RFC 7523)
An OAuth mechanism for using a signed JWT as an authorization grant at a token endpoint. In XAA, the Client presents the ID-JAG as a JWT Authorization Grant to the Resource Authorization Server's token endpoint to obtain an access token.


Implementations

IdPs (ID-JAG issuers) Clients Authorization Servers
Resource Apps SDKs Gateways Test Tools

Related Specs

Videos

Blog Posts