[Openid-aiim] Call notes
Atul Tulshibagwale
atul.tulshibagwale at crowdstrike.com
Thu Jul 16 17:13:07 UTC 2026
Hi all,
The notes for today's call are saved here
<https://github.com/openid/cg-ai-identity-management/wiki/CG-Meeting-2026%E2%80%9007-16>.
They are copied below for convenience.
Thanks to all who participated,
Atul
*AttendeesNameAffiliationParticipation Agreement signed?Atul
TulshibagwaleCrowdStrikeYesFlemming AndreasenCiscoYesDebbie
BucciIndependentYesVaibhav NarulaIndependentYesAlex
BabeanuIndykiteYesAnurag Roy BarmanIndependentYesLukasz
JarominRaidiamYesBarak ShelefOasis SecurityYesDebayan
BasuIndependentYesAgenda - News- AIIM interop event launchedNotes - IDC
Survey (Commvault sponsored)
<https://www.channelinsider.com/security/ai-identity-threats-commvault/>
talks about IAM being a key gap as perceived by C-level execs.- Interop
event blog post, participation calendar event, and details.- (Govindaraj)
Are transaction tokens included? It’s needed for delegation to sub-agents,
and those agents interact using MCP, then Transaction Tokens can preserve
the context- (Atul) Transaction Tokens is not a part of the current
interop- (Alex)- (Govindaraj) If you are delegating to an agent, you can
convey details using Transaction Tokens- (Alex) You can do that using a
simple prompt, e.g. in A2A, every request has a context id, and the context
is shared across the whole chain. The request is a JSON object, and you can
put anything in there. Not sure why Transaction Tokens- (Govindaraj) for
authenticating to MCPs.- (Alex) Authorization is missing in the interop
(AuthZen in particular)- (George) From a Txn-Token perspective, we can try
sending a Txn-Token, but those are bound to a single domain, but within the
single domain, you could encapsulate the transaction data within the tctx
of the Transaction Token. Txn-Tokens are agnostic to how the authentication
works.- (Atul) You could use the concept of the context within the token
and possibly put it in an access token, then use ID-Chaining to cross
domains.- (Alex) We use token-exchange for this, but it’s not clear whether
the “act” claim is followed- (George) Karl McGuinness has an individual
draft
<https://datatracker.ietf.org/doc/draft-mcguinness-oauth-actor-profile/>
that offers this. - (George) There is a proposed way to convert your access
token to a transaction token and back when you enter another domain. See
proposal here
<https://datatracker.ietf.org/doc/draft-fletcher-transaction-token-chaining-profile/>.-
(George) Karl’s draft is long because it has sections for Transaction
Tokens, JWT Access Tokens, etc. There are a lot of things people should
think about when proposing a solution, but putting it all within the spec
makes the spec long.*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-aiim/attachments/20260716/03cfba4f/attachment-0001.htm>
More information about the Openid-aiim
mailing list