In enterprise applications, AI agents frequently access downstream systems on behalf of users. To maintain proper security and auditing, authentication tokens must be securely exchanged and propagated across multiple architectural components, ranging from the initial client login and custom applications to identity providers, agent runtimes, custom tool implementations, and core enterprise systems.
IBM watsonx Orchestrate supports multiple OAuth-based approaches to handle identity propagation. In this context, it accommodates two primary standards:
- OAuth Token Exchange
- OAuth On-Behalf-Of
RFC 8693 is the modern vendor-neutral IETF standard, called OAuth Token Exchange, which is supported by Keycloak, Okta, Ping Identity and IBM Verify.
Microsoft Entra ID and IBM App ID do not work with RFC 8693. They support RFC 7523 and the Microsoft OBO extensions, called OAuth On-Behalf-Of.
The following sections describe and compare both alternatives. For deeper dives, refer to the related technical posts:
Protocol Comparison
OAuth Token Exchange
The following diagram describes the main components and authentication flow for token exchange.
Examples:
- Secure AI agents with IBM watsonx Orchestrate, IBM Verify, and HashiCorp Vault
- Implement secure RBAC for MCP server access using context variables and On‑Behalf‑Of (OBO) flow in watsonx Orchestrate
OAuth On-Behalf-Of
The following sequence outlines the core components and authentication flow for on-behalf-of scenarios.
Example:
Next Steps
To find out more, check out the following resources:





