OAuth2 & OpenID Connect Deep Dive · Lección

Intercambio de tokens (RFC 8693)

Aprenda la extensión de OAuth2 para el intercambio de tokens, que permite a los servicios cambiar un token por otro para admitir delegación e suplantación entre límites de servicio.

Lección 4 de 413 pasos

Intercambio de tokens (RFC 8693) es una lección gratuita de OAuth2 & OpenID Connect Deep Dive en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de OAuth2 & OpenID Connect Deep Dive, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

What Problem Does It Solve?

In a microservices world, Service A receives a token from a user, then must call Service B on the user's behalf. Forwarding the original token everywhere is risky — it may have the wrong audience or too-broad scopes.

Token Exchange (RFC 8693) lets a service trade an incoming token for a new, narrower or differently-scoped token from the authorization server.

Delegation vs Impersonation

Two distinct patterns:

  • Impersonation — the new token looks like it belongs purely to the user; downstream cannot tell a middle service was involved.
  • Delegation — the new token records both the user and the acting service via an act claim, preserving the chain.

The Grant Type

Token Exchange defines a new grant type sent to the standard token endpoint:

urn:ietf:params:oauth:grant-type:token-exchange

It does not need a browser or user interaction — it is a direct back-channel call.

Key Parameters

The request uses several parameters:

  • subject_token + subject_token_type — the token to exchange.
  • actor_token — optional, identifies the acting party.
  • audience / resource — the target service.
  • scope — requested scopes for the new token.

Token Type URIs

Token types are identified by URIs, for example:

  • urn:ietf:params:oauth:token-type:access_token
  • urn:ietf:params:oauth:token-type:jwt
  • urn:ietf:params:oauth:token-type:id_token

An Exchange Request

Service A exchanges the user's access token for a token scoped to Service B:

POST /token HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded

grant_type=urn:ietf:params:oauth:grant-type:token-exchange
&subject_token=eyJhbGciOi...
&subject_token_type=urn:ietf:params:oauth:token-type:access_token
&audience=https://serviceB.example.com
&scope=read:orders

The Exchange Response

The response includes the new token plus an issued_token_type telling the caller what it received.

{
  "access_token": "eyJ0eXAiOi...",
  "issued_token_type": "urn:ietf:params:oauth:token-type:access_token",
  "token_type": "Bearer",
  "expires_in": 600,
  "scope": "read:orders"
}

The act Claim

In delegation mode, the issued JWT contains an act (actor) claim nesting the acting party inside the subject. This lets the resource server audit who acted on whose behalf.

{
  "sub": "user-42",
  "aud": "https://serviceB.example.com",
  "act": { "sub": "service-A" }
}

Downscoping

A powerful use is downscoping: a service holding a broad token exchanges it for one with fewer scopes before passing it downstream. This honors least privilege so a compromised downstream service cannot do more than it needs.

When to Use It

Reach for Token Exchange when:

  • Crossing trust or audience boundaries between services.
  • You need an auditable delegation chain.
  • You want to narrow scopes for downstream calls.

Avoid blindly forwarding the original token across services.

Security Notes

The authorization server must authenticate the requesting client and verify it is permitted to exchange the subject token for the requested audience. Always set a correct aud so tokens cannot be replayed against other services.

Quick Check

Check your grasp of Token Exchange.

Recap

Token Exchange (RFC 8693) trades one token for another via grant type token-exchange.

  • Supports impersonation and delegation (the act claim).
  • Lets services downscope and re-audience tokens for downstream calls.
  • Requires the AS to authenticate the client and validate the target audience.
Gratis para empezar

Aprende OAuth2 & OpenID Connect Deep Dive con un tutor de IA — gratis

Escribe y ejecuta código real en tu navegador, obtén ayuda instantánea de un tutor de IA disponible 24/7 y continúa donde lo dejaste en la web o en la aplicación.

Cursos
12
Lecciones
48

Preguntas frecuentes

¿La lección «Intercambio de tokens (RFC 8693)» es gratis?

Sí — el texto completo de «Intercambio de tokens (RFC 8693)» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de OAuth2 & OpenID Connect Deep Dive, actualiza a CoddyKit PRO. El curso de OAuth2 & OpenID Connect Deep Dive incluye 4 lecciones en total.

¿Qué aprenderé en «Intercambio de tokens (RFC 8693)»?

Aprenda la extensión de OAuth2 para el intercambio de tokens, que permite a los servicios cambiar un token por otro para admitir delegación e suplantación entre límites de servicio. Practicas OAuth2 & OpenID Connect Deep Dive con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar OAuth2 & OpenID Connect Deep Dive?

No se requiere experiencia previa. OAuth2 & OpenID Connect Deep Dive en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.

¿Cuánto tiempo toma la lección «Intercambio de tokens (RFC 8693)»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de OAuth2 & OpenID Connect Deep Dive?

Sí. Cada lección de OAuth2 & OpenID Connect Deep Dive incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. PKCE para clientes públicos
  2. Tokens de actualización y scopes
  3. Credenciales de contraseña del propietario del recurso
  4. Intercambio de tokens (RFC 8693)
← Volver a OAuth2 & OpenID Connect Deep Dive