OAuth, at version 2.0 and defined in RFC 6749, with current security guidance in RFC 9700, is an authorization framework: an authorization server issues a client an access token, normally limited in scope and lifetime, so the client can call an API on a user’s behalf, or as itself, without holding the user’s password. The two grants you meet most are the authorization code grant with PKCE (RFC 7636) for a user and client credentials (RFC 6749, section 4.4) for a service. designs add a third: token exchange (RFC 8693), where a service trades the token it received for a narrower one to call the next service on the user’s behalf. OAuth on its own says nothing about who the user is; that is what OpenID Connect adds.
In an FDE interview
Okta’s three postings, as of September 2026, list OAuth 2.0, RFC 8693 token exchange, act claims and DPoP among their identity-protocol requirements. Source 1Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 2Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 3Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting OAuth decides the design whenever your system calls customer systems, for example an agent that reads email, calendars and tickets, where the weak answer runs every call through one shared service account. A strong candidate gives each user’s actions that user’s delegated token with the narrowest scopes, gives machine-to-machine jobs their own client identity, and says where refresh tokens are stored and how they are revoked (RFC 7009).
Delegated tokens are not enough if the agent searches an index built with an admin account: the leak is in the shared index, so filter retrieval by the requesting user’s permissions at query time, or index per user. When the agent calls a downstream service, exchange the user’s token for a narrower one with an act claim naming the agent, so the audit log shows the agent acting for that user rather than the user alone. When a refresh fails, ask the user to consent again; never fall back to the service account.
The lesson Identity and network in someone else’s environment covers service identities, OAuth and token exchange, and a planned multi-tenant agent isolation design prompt will be the practice.