Safety & Security · Data artifact

Scoped Access Token

Data artifactSafety & SecuritySafety, Security & Governancearc:ScopedAccessToken

A short-lived credential carrying only the specific OAuth 2.0 scopes (e.g., read:calendar) an agent capability requires.

Responsibility. Restricts API operations an agent can perform to its granted scopes.

Also known as: OAuth 2.0 scoped token, Short-lived scoped credential

constrainsis written byAgent Controller: constrainsAgent ControllerIdentity Provider: is written byIdentity Provider
Direct neighbourhood (hover for relationship types)

Relationships

is written by dependency

constrains control

Design guidance

Classification

Patterns
OAuth 2.0 scopesShort-lived credentials
Risks mitigated
Monolithic full-access tokensCredential theft and long-term misuse
Frameworks & regulations
OAuth 2.0

Sources

  1. Ch9.2: T. Nguyen, "Action Constraints and Permission Models," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.2. ISBN: 9798244538229.
  2. Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.