トークン交換(RFC 8693)
サービス間の委任やなりすましを実現するために、サービスがあるトークンを別のトークンに交換できるOAuth2 Token Exchange拡張を学びます。
「トークン交換(RFC 8693)」はCoddyKit上の無料OAuth2 & OpenID Connect Deep Diveレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはOAuth2 & OpenID Connect Deep Dive学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
What Problem Does It Solve?
In a microservices world, Service A receives a token from a user, then must call Service B on the user's behalf. Forwarding the original token everywhere is risky — it may have the wrong audience or too-broad scopes.
Token Exchange (RFC 8693) lets a service trade an incoming token for a new, narrower or differently-scoped token from the authorization server.
Delegation vs Impersonation
Two distinct patterns:
- Impersonation — the new token looks like it belongs purely to the user; downstream cannot tell a middle service was involved.
- Delegation — the new token records both the user and the acting service via an
actclaim, preserving the chain.
The Grant Type
Token Exchange defines a new grant type sent to the standard token endpoint:
urn:ietf:params:oauth:grant-type:token-exchange
It does not need a browser or user interaction — it is a direct back-channel call.
Key Parameters
The request uses several parameters:
subject_token+subject_token_type— the token to exchange.actor_token— optional, identifies the acting party.audience/resource— the target service.scope— requested scopes for the new token.
Token Type URIs
Token types are identified by URIs, for example:
urn:ietf:params:oauth:token-type:access_tokenurn:ietf:params:oauth:token-type:jwturn:ietf:params:oauth:token-type:id_token
An Exchange Request
Service A exchanges the user's access token for a token scoped to Service B:
POST /token HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded
grant_type=urn:ietf:params:oauth:grant-type:token-exchange
&subject_token=eyJhbGciOi...
&subject_token_type=urn:ietf:params:oauth:token-type:access_token
&audience=https://serviceB.example.com
&scope=read:ordersThe Exchange Response
The response includes the new token plus an issued_token_type telling the caller what it received.
{
"access_token": "eyJ0eXAiOi...",
"issued_token_type": "urn:ietf:params:oauth:token-type:access_token",
"token_type": "Bearer",
"expires_in": 600,
"scope": "read:orders"
}The act Claim
In delegation mode, the issued JWT contains an act (actor) claim nesting the acting party inside the subject. This lets the resource server audit who acted on whose behalf.
{
"sub": "user-42",
"aud": "https://serviceB.example.com",
"act": { "sub": "service-A" }
}Downscoping
A powerful use is downscoping: a service holding a broad token exchanges it for one with fewer scopes before passing it downstream. This honors least privilege so a compromised downstream service cannot do more than it needs.
When to Use It
Reach for Token Exchange when:
- Crossing trust or audience boundaries between services.
- You need an auditable delegation chain.
- You want to narrow scopes for downstream calls.
Avoid blindly forwarding the original token across services.
Security Notes
The authorization server must authenticate the requesting client and verify it is permitted to exchange the subject token for the requested audience. Always set a correct aud so tokens cannot be replayed against other services.
Quick Check
Check your grasp of Token Exchange.
Recap
Token Exchange (RFC 8693) trades one token for another via grant type token-exchange.
- Supports impersonation and delegation (the
actclaim). - Lets services downscope and re-audience tokens for downstream calls.
- Requires the AS to authenticate the client and validate the target audience.
AI チューターと学ぶ OAuth2 & OpenID Connect Deep Dive — 無料
ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。
- コース
- 12
- レッスン
- 48
よくある質問
「トークン交換(RFC 8693)」レッスンは無料ですか?
はい。「トークン交換(RFC 8693)」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、OAuth2 & OpenID Connect Deep Diveコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 OAuth2 & OpenID Connect Deep Diveコースには全4レッスンが含まれています。
「トークン交換(RFC 8693)」で何を学びますか?
サービス間の委任やなりすましを実現するために、サービスがあるトークンを別のトークンに交換できるOAuth2 Token Exchange拡張を学びます。 ブラウザで直接実行するハンズオンコードでOAuth2 & OpenID Connect Deep Diveを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
OAuth2 & OpenID Connect Deep Diveを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのOAuth2 & OpenID Connect Deep Diveは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。
「トークン交換(RFC 8693)」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このOAuth2 & OpenID Connect Deep Diveレッスンでコードを書いて実行できますか?
はい。すべてのOAuth2 & OpenID Connect Deep Diveレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。