Token Exchange Grant Type: Identity Assertion JWT Authorization Grant

ID-JAG support enables a controlled, short-lived identity handoff across trust domains. The source controls what the signed grant carries; the target independently controls whether it becomes an OAuth access token.

Overview

Identity Assertion JWT Authorization Grant (ID-JAG) is a profile of the JWT Authorization Grant that lets a client obtain delegated access to a resource in another trust domain on behalf of a user, without a direct user-approval step at the target Authorization Server. It is issued and signed by the IdP Authorization Server and is an intermediate authorization grant—not an OAuth Bearer access token.

In the Cross-App Access (XAA) pattern, a client coordinates through an IdP that both applications trust for SSO and subject resolution. The Resource Authorization Server retains independent control over whether to honor the ID-JAG and which OAuth access token, scopes, or permissions to issue.

ID-JAG support enables a controlled, short-lived identity handoff across trust domains. The source controls what the signed grant carries; the target independently controls whether it becomes an OAuth access token.

End-to-end flow

1. Source Identity Domain Validate the domain-issued ID Token and mint an ID-JAG. → 2. Target Identity Domain Validate and redeem the ID-JAG for an OAuth Bearer access token.

Important distinctions

  • An ID-JAG is a signed intermediate authorization grant, not a Bearer access token.
  • A raw external OIDC ID Token is not an ID-JAG. Do not submit it to either exchange as an ID-JAG.
  • A compatible ID-JAG from an external IdP can be redeemed only when the target has a matching active inbound Identity Propagation Trust.
  • Use the resulting OAuth Bearer access token—not the ID-JAG—to call the protected target API.

Before you begin

  • Use a confidential OAuth client for the runtime exchange.
  • Configure an active outbound trust for issuance or inbound trust for redemption, with the required client, scope, resource and issuer.