OAuth Is Not Enough Authorization Challenges for Autonomous AI Agents
Vivek Chopra · 2025
Recent publications on AI Agents are anchoring on OAuth, specifically OAuth 2.1, for delegated access. The paper identifies key limitations of OAuth in this context, including coarse permission scopes, lack of dynamic policy enforcement, and insufficient support for multi-hop delegation of authority. It then proposes complementary mechanisms such as policy-as-code enforcement, enhanced token delegation flows, and secure AI agent architecture patterns to address these gaps. This approach aligns with emerging industry standards and research, maintaining compatibility with existing OAuth infrastructure, while extending it to ensure AI agents act within human-intended bounds. The analysis concludes that securing AI agents requires a layered authorization stack that extends beyond OAuth alone.