Token Exchange Grant Type: Identity Assertion JWT Authorization Grant
ID-JAG support enables a controlled, short-lived identity handoff across trust domains. The source controls what the signed grant carries; the target independently controls whether it becomes an OAuth access token.
Overview
Identity Assertion JWT Authorization Grant (ID-JAG) is a profile of the JWT Authorization Grant that lets a client obtain delegated access to a resource in another trust domain on behalf of a user, without a direct user-approval step at the target Authorization Server. It is issued and signed by the IdP Authorization Server and is an intermediate authorization grant—not an OAuth Bearer access token.
In the Cross-App Access (XAA) pattern, a client coordinates through an IdP that both applications trust for SSO and subject resolution. The Resource Authorization Server retains independent control over whether to honor the ID-JAG and which OAuth access token, scopes, or permissions to issue.
ID-JAG support enables a controlled, short-lived identity handoff across trust domains. The source controls what the signed grant carries; the target independently controls whether it becomes an OAuth access token.
Choose the right exchange flow
| Starting point | What you need to do | Guide |
|---|---|---|
| An ID Token issued by a source Oracle Identity Domain | Exchange it for a signed ID-JAG. | Token Exchange Grant Type: Exchanging Identity Token for Identity Assertion JWT Authorization Grant |
| A compatible ID-JAG, including one from a trusted external IdP | Redeem it at the target Identity Domain for an OAuth access token. | Token Exchange Grant Type: Exchanging Identity Assertion JWT Authorization Grant for OAuth Access Token |
End-to-end flow
| 1. Source Identity Domain Validate the domain-issued ID Token and mint an ID-JAG. | → | 2. Target Identity Domain Validate and redeem the ID-JAG for an OAuth Bearer access token. |
Important distinctions
- An ID-JAG is a signed intermediate authorization grant, not a Bearer access token.
- A raw external OIDC ID Token is not an ID-JAG. Do not submit it to either exchange as an ID-JAG.
- A compatible ID-JAG from an external IdP can be redeemed only when the target has a matching active inbound Identity Propagation Trust.
- Use the resulting OAuth Bearer access token—not the ID-JAG—to call the protected target API.
Before you begin
- Use a confidential OAuth client for the runtime exchange.
- Configure an active outbound trust for issuance or inbound trust for redemption, with the required client, scope, resource and issuer.