A scoped credential is a credential limited in time, action, amount, or data scope — for example, “pay up to €200 for a train ticket today”, rather than “act as the user”.
Why it matters
Least authority is the single most effective limit on agent damage. If an agent is manipulated or goes wrong, a scoped credential bounds the blast radius: it cannot exceed its mandate even if the agent’s reasoning fails.
Scoping has an established toolkit:
- OAuth scopes (RFC 6749) are the classic mechanism to limit token permissions.
- Rich Authorization Requests (RFC 9396) let a client request fine-grained, structured authorization data in OAuth messages rather than coarse static scopes.
- The MCP authorization spec recommends selecting the minimum required scopes for an operation and performing step-up authorization only when more is needed.
- Payment mandates (e.g. AP2) bind an agent to a specific cart, amount, and payment intent.
Dimensions to scope
- Time — a short validity window.
- Action — the permitted operations only.
- Amount — monetary or usage caps.
- Data — the minimum fields or resources needed.
- Audience — the specific service(s) the credential is valid for.
How it works in practice
Scoping is applied at issuance, not left to the agent’s judgement. OAuth issues a token with a scope set; Rich Authorization Requests go further and let the client request structured detail such as a specific amount and payee, so the authorization server can issue a narrowly bounded grant. MCP’s authorization guidance takes the least-privilege line: request the minimum scopes for the operation and step up only when a larger action is genuinely needed.
The same idea appears in the failure literature: static, long-lived, over-broad secrets are exactly what OWASP’s non-human identity risks warn about, because a leaked key carries all their permissions at once. A short window plus narrow scope keeps a single compromised credential from becoming a fleet-wide problem. See What is Know Your Agent? and the verification guide, with scoping code in the examples.
Related terms
Sources
- IETF, RFC 9396, OAuth 2.0 Rich Authorization Requests (accessed 2026-10-03)
- IETF, RFC 6749, The OAuth 2.0 Authorization Framework (accessed 2026-10-03)
- Model Context Protocol, Authorization (accessed 2026-10-03)
- Google, Agent Payments Protocol (AP2) (accessed 2026-10-03)
- OWASP, Non-Human Identities Top 10 (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.