OAuth Is Asking What Authorization Needs to Become
Learn why OAuth is being pushed to reconsider what authorization needs to become as software grows more autonomous. Heather examines recent OAuth working group discussions around proof of possession, HTTP message signatures, threat models, and the architectural question of where software identity should live.
The episode explores how agentic AI complicates delegated authorization, particularly when multiple software actors, permissions, and contexts are involved. Heather considers whether OAuth needs new extensions or whether some problems belong elsewhere, and why defining clear boundaries may matter more than creating another protocol.









