A scoped credential is a credential limited in time, action, amount, or data scope — for example, “pay up to €200 for a train ticket today”, rather than “act as the user”.
Why it matters
Least authority is the single most effective limit on agent damage. If an agent is manipulated or goes wrong, a scoped credential bounds the blast radius: it cannot exceed its mandate even if the agent’s reasoning fails.
Scoping has an established toolkit:
- OAuth scopes (RFC 6749) are the classic mechanism to limit token permissions.
- Rich Authorization Requests (RFC 9396) let a client request fine-grained, structured authorization data in OAuth messages rather than coarse static scopes.
- The MCP authorization spec recommends selecting the minimum required scopes for an operation and performing step-up authorization only when more is needed.
- Payment mandates (e.g. AP2) bind an agent to a specific cart, amount, and payment intent.
Dimensions to scope
- Time — a short validity window.
- Action — the permitted operations only.
- Amount — monetary or usage caps.
- Data — the minimum fields or resources needed.
- Audience — the specific service(s) the credential is valid for.
Related
Sources
- IETF, RFC 9396, Rich Authorization Requests — https://www.rfc-editor.org/info/rfc9396/ (accessed 2026-10-03)
- IETF, RFC 6749, The OAuth 2.0 Authorization Framework — https://www.rfc-editor.org/rfc/rfc6749 (accessed 2026-10-03)
- Model Context Protocol, Authorization — https://modelcontextprotocol.io/specification/draft/basic/authorization (accessed 2026-10-03)
- Google, Agent Payments Protocol (AP2) — https://ap2-protocol.org/ (accessed 2026-10-03)