Platform · Open standards

Standards, protocols, and technical differentiation

Which IETF, OpenID Foundation, and industry specifications EmpowerID Identity Fabric implements—and how they compose on one governance spine for workforce, partner, workload, and AI agent identities.

SOC 2, ISO 27001, and commercial licensing are documented separately. This page is protocol inventory, composition, and maturity for technical evaluation.

Open standards at the boundaries; one event-driven governance spine—so any front door, whether ServiceNow, SAP GRC, SailPoint, Microsoft Copilot, a custom portal, or an AI agent, uses the same authorization contract and produces the same auditable outcomes.

Publication July 28, 2026 · Version 1.1 · Download evaluation brief (PDF) (521 KB)

AuthZEN OAuth 2.1 OIDC ID-JAG / XAA MCP 2026 preview SSF / CAEP SCIM RFC 9207

For evaluators

Why standards matter for buyers

Enterprise and partner evaluators need more than a checkbox that says “OAuth supported.” EmpowerID Identity Fabric is standards-first at every integration boundary—with centralized policy and tamper-evident evidence as platform primitives.

Inventory

Which specifications apply to authentication, authorization, provisioning, continuous access, agent tools, and audit evidence—and at what maturity.

Composition

How those specifications connect in one architecture rather than as disconnected optional modules.

Differentiation

What is structurally different from legacy IGA suites and agent-only gateways, expressed in protocol and proof terms.

Executive summary by domain

Representative open standards and how they differentiate on the fabric—not disconnected optional modules.

Identity & authentication

Representative standards

OpenID Connect, OAuth 2.1, WebAuthn/FIDO2, CIBA, PKCE, PAR, DPoP, JARM, RAR, token exchange, introspection

Why it differentiates

Deep OAuth/OIDC surface while coexisting with the workforce IdP—the fabric federates rather than forcing rip-and-replace.

Authorization

Representative standards

OpenID AuthZEN (evaluate, batch, search); PBAC / ABAC / RBAC / ReBAC

Why it differentiates

One externalized Policy Decision Point for applications, IGA guardrails, SoD, search scoping, delegation, and agent enforcement.

Cross-app & agent identity

Representative standards

RFC 8693, On-Behalf-Of, ID-JAG (same wire as Okta Cross-App Access), RFC 9728 resource metadata, RFC 7523 JWT bearer at resource authorization servers, RFC 9207 issuer identification

Why it differentiates

Issue and consume ID-JAG at governed tool, orchestration, and AI gateway edges; AuthZEN at mint and on each action.

Continuous access

Representative standards

OpenID SSF 1.0, CAEP-aligned Security Event Tokens, RFC 8935 push, RFC 9493 subjects

Why it differentiates

Verified signal → policy → enforcement (push transmit/receive in production).

Provisioning & directory

Representative standards

SCIM 2.0, LDAP v3, virtual directory

Why it differentiates

Configuration-driven connectors and graph-backed membership—not a monolithic identity warehouse.

Agent execution

Representative standards

Model Context Protocol (MCP) incl. 2026-07-28 revision, MCP enterprise-managed authorization (EMA) grant profiles, OAuth 2.1 at the gateway, RFC 8693 delegation narrowing

Why it differentiates

Dual policy enforcement (model traffic + tool calls) with capability without custody—credentials are not returned to the agent.

Evidence

Representative standards

JWS (RS256), hash-chained receipts, JWKS verification, SCITT-upgradeable receipt format

Why it differentiates

Linked decision → execution → verification chain, not audit logs alone.

Design principles

The Identity Fabric reference model expects composable, API-first services for all identity types—integrated by policy and orchestration, not shared databases.

Principle What to verify
API and event parity Governed actions are available via documented APIs and asynchronous events

Security is not UI-only; integrators and agents are first-class callers.

Contract integration Services integrate via APIs and events, not shared databases

AuthZEN, SCIM, and LDAP at boundaries; propagation via events.

Bring-your-own front door Existing ITSM, GRC, or IGA portals can drive the same workflows

Same authorization contracts for human UI and machine callers.

Fail-closed enforcement Deny when the decision service is unavailable, where policy requires

Obligations (step-up MFA, audit) enforced at the Policy Enforcement Point.

Explicit maturity Draft and roadmap items are labeled as such

ID-JAG is an implemented IETF draft; FAPI alignment is not formal FAPI certification.

How standards compose

Front doors (ITSM, GRC, IGA, custom UI, agents) enter via OIDC/OAuth, ID-JAG, and delegation. AuthZEN evaluates across federation and authorization services. SSF/CAEP feeds continuous policy; MCP, SCIM, and LDAP fulfill at the edge; JWS receipts close the proof loop.

  • Documented APIs and events—not peer database access
  • Constraints and obligations at the PEP
  • Same contract for human UI and machine callers
How the Fabric works →

Standards inventory

Browse by domain

Maturity tags reflect deployment status as of July 28, 2026. Draft and roadmap items are labeled explicitly—see scope statements before RFP reuse.

ProductionImplementedEmerging / draftRoadmapPartial

Authentication & session

Identity & Federation Service — OIDC/OAuth-first integration.

Standard / specificationPlatform roleMaturity
OpenID ConnectSSO and ID tokensProduction
OAuth 2.1Authorization code, client credentials, token endpointsProduction
PKCE (RFC 7636)Public and native client protectionProduction
PAR (RFC 9126)Pushed authorization requestsProduction
JARMJWT-secured authorization responseProduction
private_key_jwtConfidential client authenticationProduction
CIBA (OpenID)Decoupled / out-of-band authenticationProduction
WebAuthn / FIDO2Passkeys; passwordless-capable authenticationProduction
TOTPAuthenticator-app MFAProduction
Temporary Access PassBootstrap and recoveryProduction
DPoP (RFC 9449)Sender-constrained tokens

Composable with token exchange and ID-JAG

Production
Token introspection (RFC 7662)Resource-server validationProduction
JWT / JWS / JWKSSigning, verification, key rotationProduction

Appendix

Master reference

Quick lookup for RFCs, OpenID profiles, and platform roles—searchable for architects and integrators.

25 entries

RFC 7636

PKCE

OAuth public clients

RFC 7662

Token introspection

Resource validation

RFC 7523

JWT bearer grant

ID-JAG Step 2 at resource AS

RFC 8693

OAuth 2.0 Token Exchange

Delegation, OBO, ID-JAG Step 1, agents

RFC 8707

Resource Indicators

Audience binding

RFC 8935

SET Push Delivery

SSF push

RFC 8936

SET Poll Delivery

Roadmap

RFC 9126

PAR

Pushed authorization requests

RFC 9396

RAR

Rich authorization requests

RFC 9449

DPoP

Sender-constrained tokens

RFC 9207

OAuth 2.0 Authorization Server Issuer

Mix-up defence; MCP edge hardening

RFC 9493

Subject identifiers

SSF/CAEP subjects

RFC 9728

Protected Resource Metadata

ID-JAG discovery

OAuth 2.1

OAuth consolidation (IETF)

Platform baseline

OIDC

OpenID Connect

SSO, ID tokens

CIBA

Client Initiated Backchannel Authentication

Decoupled authentication

WebAuthn / FIDO2

W3C / FIDO Alliance

Passkeys

JARM

JWT Secured Authorization Response

Authorization response mode

AuthZEN

OpenID Authorization API

PDP evaluate / search / batch

SSF 1.0

Shared Signals Framework

Continuous access transport

CAEP

Continuous Access Evaluation Profile

Event semantics

SCIM 2.0

System for Cross-domain Identity Management

Provisioning

LDAP v3

Lightweight Directory Access Protocol

Virtual directory

MCP

Model Context Protocol

Agent tools

ID-JAG

Identity Assertion Authorization Grant (IETF draft)

Cross-app access (XAA wire)

Technical differentiation

Compared with common market patterns—expressed in protocol and proof terms, not marketing slogans.

Legacy IGA / IAM suites

Common suite pattern Identity Fabric pattern Standards angle
Monolith with embedded RBAC Externalized AuthZEN PDP Open evaluation and search APIs; policies as versioned configuration
Overnight batch SoD Preventive SoD at PDP (milliseconds, fail-closed) Same engine as application authorization
Single relational identity warehouse Graph + transactional grants + analytics evidence store LDAP/SCIM at the edge; events for propagation
Governance only through vendor UI Bring-your-own front door + API/event parity ID-JAG and MCP for non-human callers
Agents added later Agent Governance & Execution on the same spine MCP, RFC 8693, ID-JAG, Credential Control

Agent-only gateways

Common gateway pattern Fabric pattern Standards angle
Tool routing and static API keys Governed Tool Gateway PEP + AuthZEN per tool MCP + OAuth + AuthZEN
Credentials held in the agent Capability without custody Token exchange; secrets not returned to the agent
Weak enterprise IGA Entitlement ledger and access certification engines SCIM/LDAP fulfillment with proof chain
Ad hoc cross-app trust ID-JAG issue and consume on resource planes Same IETF draft wire as industry Cross-App Access
Foreign agent tokens trusted implicitly Inbound federation materializes a governed local identity with delegation lineage RFC 7523 jwt-bearer; foreign JWKS validation, typ gate, replay control, capability ∩ ceiling
Identity governed, model runtime ungoverned Same PEP governs the agent’s model traffic across cloud providers Kill switch, budget hold, per-turn signed receipt on a verified delegated identity

Beyond “we support OAuth”

Differentiation is composition:

  1. 1 ID-JAG + AuthZEN — cross-app identity leg plus per-action authorization.
  2. 2 Constraints and obligations — enforced in standard deployment, not optional demos.
  3. 3 SSF/CAEP → policy → enforce — continuous access as verified signals, not session TTL alone.
  4. 4 Proof chain — signed receipts linked to decisions and fulfillment.

Reference deployments

Protocol scale (illustrative)

Mid-2026 baseline metrics—your sizing may differ.

15+

Independently deployable fabric services

115 / 227

AuthZEN application contracts / policies

30+

Event topics in production

176,000+

Dynamic group (ABAC) rules via events

167+ (400+ definitions on full surface)

MCP tools via Governed Tool Gateway

Sub-10 ms

Typical PDP decision latency

Under 5 seconds

Typical search index lag

Maturity & scope statements

Read before RFP reuse—accurate claims only.

FAPI

Aligned building blocks and automated tests — not formal OpenID FAPI product certification.

ID-JAG / XAA

IETF draft; interoperable with Okta Cross-App Access wire; issuance production-grade; consumption live-verified with ongoing hardening.

MCP 2026 transport

Governance-first preview slice; the public conformance suite has not been passed—no “MCP 2026 certified”, “passed the official suite”, or “first to” claim is authorized.

MCP EMA

Grant profiles are advertised on protected-resource metadata; two-sided interop with an external IdP/client is not complete—no “EMA certified” claim.

Inbound agent federation

On-behalf-of and autonomous foreign-agent paths are live and hardened; the public trust framework for foreign issuers continues to mature.

SSF

Push transmit/receive in production; poll, RISC, and stream management on roadmap; continuous enforcement scope is expanding.

SoD

Engine production-ready; customer/function catalog content must be populated for turnkey rule libraries.

Access certification

Engine production-ready; production certification campaigns depend on customer rollout.

Privileged access

Governed secrets vault, disclosure, and secretless agent access in production; session recording, shared-account checkout, and rotation automation on roadmap.

Connector catalog

Depth and configuration velocity versus incumbent SKU count—position with evidence, not parity claims.

Decentralized identity / verifiable credentials

Not a current fabric focus; enterprise federation via OIDC (and SAML where deployed).

Suggested 90-minute deep-dive

Agenda for security architects and integration leads.

  1. 0–15 min Identity Fabric thesis and bring-your-own front door
  2. 15–35 min AuthZEN, constraints, obligations, enforcement map
  3. 35–50 min ID-JAG / Cross-App Access — issue and consume
  4. 50–65 min SSF / CAEP continuous access
  5. 65–80 min Agent governance — MCP, Credential Control, dual PEP
  6. 80–90 min Maturity, roadmap, and partner deployment models
Schedule technical session

FAQs

Does EmpowerID replace my workforce identity provider?

No. Identity Fabric federates with Okta, Microsoft Entra, and other IdPs. OAuth/OIDC and token exchange let you keep the front door you already operate while centralizing authorization, orchestration, and evidence on the fabric spine.

How is AuthZEN used beyond application RBAC?

One PDP evaluates application access, IGA guardrails, SoD, search post-authorization filtering, delegation constraints, and agent tool invocation— with obligations enforced at each Policy Enforcement Point.

What is ID-JAG in practical terms?

ID-JAG answers which application may call which API on whose behalf, using short-lived audience-bound assertions. It is one credential leg; AuthZEN still decides each action at mint and at consumption.

How does ID-JAG relate to Okta Cross-App Access (XAA)?

Same protocol family on the wire: ID-JAG is the IETF draft name; XAA is Okta’s product name. EmpowerID implements ID-JAG issuance and consumption and interoperates with XAA-style requests. Okta leads ecosystem distribution; Identity Fabric leads governed authorization depth, delegation, and receipts alongside the workforce IdP—not a connector-count comparison.

Is EmpowerID “MCP 2026 certified”?

No. MCP 2026 transport is a governance-first preview slice on the Governed Tool Gateway; the public conformance suite has not been passed. No “MCP 2026 certified”, “passed the official suite”, or “first to” claim is authorized. Ask any vendor for the test artifact—not the adjective.

Is formal OpenID FAPI certification claimed?

No. The platform uses FAPI-aligned building blocks (PAR, DPoP, JARM, private_key_jwt) with automated baseline tests—not a formal OpenID FAPI product certification claim.

Where do SOC 2 and ISO 27001 fit?

Certifications and audit reports are covered on Trust & Compliance surfaces and in sales packages. This standards page focuses on protocol inventory and architecture composition.

This page describes product capabilities as of July 28, 2026. Specifications marked draft or roadmap may change. Metrics are illustrative. Nothing herein modifies a signed agreement.

Get Started

Schedule a standards deep-dive

Walk through AuthZEN, ID-JAG, SSF/CAEP, and agent governance on your evaluation agenda—with protocol conformance scope and declared-path evidence on Trust.

Request Demo See the platform in action
Download evaluation brief Technical consultation
EmpowerID AI

EmpowerID AI Assistant

Online

EmpowerID AI
EmpowerID AI
Hello! How can I help you today?
11:19 PM

Suggested questions:

Powered by EmpowerID AI