AI Agent OAuth Scopes and Permission Boundaries for Tool-Calling
Delegated tokens alone won't stop agents from accessing data they shouldn't at execution time.
Marta Żukowska
Staff Writer
Marta holds a background in applied cryptography research and transitioned to security journalism after co-authoring tooling for automated token inspection at a Warsaw-based fintech startup. She focuses on the lifecycle and abuse patterns of bearer tokens, JWTs, and refresh token chains.
1 story
Delegated tokens alone won't stop agents from accessing data they shouldn't at execution time.