Safety & Security · Data artifact
Scoped Access Token
Data artifactSafety & SecuritySafety, Security & Governancearc:ScopedAccessToken
A short-lived credential carrying only the specific OAuth 2.0 scopes (e.g., read:calendar) an agent capability requires.
Responsibility. Restricts API operations an agent can perform to its granted scopes.
Also known as: OAuth 2.0 scoped token, Short-lived scoped credential
Relationships
is written by dependency
constrains control
- Agent Controller abstract Ch9.2
Design guidance
- SHOULD issue per-capability scopes rather than monolithic full-access tokens.
Classification
- Patterns
- OAuth 2.0 scopesShort-lived credentials
- Risks mitigated
- Monolithic full-access tokensCredential theft and long-term misuse
- Frameworks & regulations
- OAuth 2.0
Sources
- Ch9.2: T. Nguyen, "Action Constraints and Permission Models," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.2. ISBN: 9798244538229.
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.