heidloff.net - Building is my Passion
Post
Cancel

Passing User Identity safely across Agents and Enterprise Systems

In enterprise applications, AI agents frequently access downstream systems on behalf of users. To maintain proper security and auditing, authentication tokens must be securely exchanged and propagated across multiple architectural components, ranging from the initial client login and custom applications to identity providers, agent runtimes, custom tool implementations, and core enterprise systems.

IBM watsonx Orchestrate supports multiple OAuth-based approaches to handle identity propagation. In this context, it accommodates two primary standards:

RFC 8693 is the modern vendor-neutral IETF standard, called OAuth Token Exchange, which is supported by Keycloak, Okta, Ping Identity and IBM Verify.

Microsoft Entra ID and IBM App ID do not work with RFC 8693. They support RFC 7523 and the Microsoft OBO extensions, called OAuth On-Behalf-Of.

The following sections describe and compare both alternatives. For deeper dives, refer to the related technical posts:

Protocol Comparison

image

OAuth Token Exchange

The following diagram describes the main components and authentication flow for token exchange.

image

image

Examples:

OAuth On-Behalf-Of

The following sequence outlines the core components and authentication flow for on-behalf-of scenarios.

image

image

Example:

Next Steps

To find out more, check out the following resources:

Featured Blog Posts
Disclaimer
The postings on this site are my own and don’t necessarily represent IBM’s positions, strategies or opinions.
Contents
Trending Tags