تبادل الرموز (RFC 8693)
تعلّموا امتداد تبادل الرموز في OAuth2، الذي يتيح للخدمات استبدال رمز بآخر لدعم التفويض وانتحال الهوية عبر حدود الخدمات.
تبادل الرموز (RFC 8693) درس مجاني في OAuth2 & OpenID Connect Deep Dive على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في OAuth2 & OpenID Connect Deep Dive، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة OAuth2 & OpenID Connect Deep Dive 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
What Problem Does It Solve?
In a microservices world, Service A receives a token from a user, then must call Service B on the user's behalf. Forwarding the original token everywhere is risky — it may have the wrong audience or too-broad scopes.
Token Exchange (RFC 8693) lets a service trade an incoming token for a new, narrower or differently-scoped token from the authorization server.
Delegation vs Impersonation
Two distinct patterns:
- Impersonation — the new token looks like it belongs purely to the user; downstream cannot tell a middle service was involved.
- Delegation — the new token records both the user and the acting service via an
actclaim, preserving the chain.
The Grant Type
Token Exchange defines a new grant type sent to the standard token endpoint:
urn:ietf:params:oauth:grant-type:token-exchange
It does not need a browser or user interaction — it is a direct back-channel call.
Key Parameters
The request uses several parameters:
subject_token+subject_token_type— the token to exchange.actor_token— optional, identifies the acting party.audience/resource— the target service.scope— requested scopes for the new token.
Token Type URIs
Token types are identified by URIs, for example:
urn:ietf:params:oauth:token-type:access_tokenurn:ietf:params:oauth:token-type:jwturn:ietf:params:oauth:token-type:id_token
An Exchange Request
Service A exchanges the user's access token for a token scoped to Service B:
POST /token HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded
grant_type=urn:ietf:params:oauth:grant-type:token-exchange
&subject_token=eyJhbGciOi...
&subject_token_type=urn:ietf:params:oauth:token-type:access_token
&audience=https://serviceB.example.com
&scope=read:ordersThe Exchange Response
The response includes the new token plus an issued_token_type telling the caller what it received.
{
"access_token": "eyJ0eXAiOi...",
"issued_token_type": "urn:ietf:params:oauth:token-type:access_token",
"token_type": "Bearer",
"expires_in": 600,
"scope": "read:orders"
}The act Claim
In delegation mode, the issued JWT contains an act (actor) claim nesting the acting party inside the subject. This lets the resource server audit who acted on whose behalf.
{
"sub": "user-42",
"aud": "https://serviceB.example.com",
"act": { "sub": "service-A" }
}Downscoping
A powerful use is downscoping: a service holding a broad token exchanges it for one with fewer scopes before passing it downstream. This honors least privilege so a compromised downstream service cannot do more than it needs.
When to Use It
Reach for Token Exchange when:
- Crossing trust or audience boundaries between services.
- You need an auditable delegation chain.
- You want to narrow scopes for downstream calls.
Avoid blindly forwarding the original token across services.
Security Notes
The authorization server must authenticate the requesting client and verify it is permitted to exchange the subject token for the requested audience. Always set a correct aud so tokens cannot be replayed against other services.
Quick Check
Check your grasp of Token Exchange.
Recap
Token Exchange (RFC 8693) trades one token for another via grant type token-exchange.
- Supports impersonation and delegation (the
actclaim). - Lets services downscope and re-audience tokens for downstream calls.
- Requires the AS to authenticate the client and validate the target audience.
الأسئلة الشائعة
هل درس «تبادل الرموز (RFC 8693)» مجاني؟
نعم — نص درس «تبادل الرموز (RFC 8693)» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة OAuth2 & OpenID Connect Deep Dive، انتقل إلى CoddyKit PRO. تتضمن دورة OAuth2 & OpenID Connect Deep Dive 4 دروس في المجموع.
ماذا ستتعلم في «تبادل الرموز (RFC 8693)»؟
تعلّموا امتداد تبادل الرموز في OAuth2، الذي يتيح للخدمات استبدال رمز بآخر لدعم التفويض وانتحال الهوية عبر حدود الخدمات. تتمرن على OAuth2 & OpenID Connect Deep Dive مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ OAuth2 & OpenID Connect Deep Dive؟
لا تُشترط خبرة سابقة. OAuth2 & OpenID Connect Deep Dive على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.
كم من الوقت يستغرق درس «تبادل الرموز (RFC 8693)»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس OAuth2 & OpenID Connect Deep Dive هذا؟
نعم. كل درس في OAuth2 & OpenID Connect Deep Dive يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- PKCE للعملاء العامين
- رموز التحديث والنطاقات
- بيانات اعتماد كلمة مرور مالك المورد
- تبادل الرموز (RFC 8693)