Inventory
Which specifications apply to authentication, authorization, provisioning, continuous access, agent tools, and audit evidence—and at what maturity.
Platform · Open standards
Which IETF, OpenID Foundation, and industry specifications EmpowerID Identity Fabric implements—and how they compose on one governance spine for workforce, partner, workload, and AI agent identities.
SOC 2, ISO 27001, and commercial licensing are documented separately. This page is protocol inventory, composition, and maturity for technical evaluation.
Open standards at the boundaries; one event-driven governance spine—so any front door, whether ServiceNow, SAP GRC, SailPoint, Microsoft Copilot, a custom portal, or an AI agent, uses the same authorization contract and produces the same auditable outcomes.
Publication July 28, 2026 · Version 1.1 · Download evaluation brief (PDF) (521 KB)
For evaluators
Enterprise and partner evaluators need more than a checkbox that says “OAuth supported.” EmpowerID Identity Fabric is standards-first at every integration boundary—with centralized policy and tamper-evident evidence as platform primitives.
Which specifications apply to authentication, authorization, provisioning, continuous access, agent tools, and audit evidence—and at what maturity.
How those specifications connect in one architecture rather than as disconnected optional modules.
What is structurally different from legacy IGA suites and agent-only gateways, expressed in protocol and proof terms.
Representative open standards and how they differentiate on the fabric—not disconnected optional modules.
Representative standards
OpenID Connect, OAuth 2.1, WebAuthn/FIDO2, CIBA, PKCE, PAR, DPoP, JARM, RAR, token exchange, introspection
Why it differentiates
Deep OAuth/OIDC surface while coexisting with the workforce IdP—the fabric federates rather than forcing rip-and-replace.
Representative standards
OpenID AuthZEN (evaluate, batch, search); PBAC / ABAC / RBAC / ReBAC
Why it differentiates
One externalized Policy Decision Point for applications, IGA guardrails, SoD, search scoping, delegation, and agent enforcement.
Representative standards
RFC 8693, On-Behalf-Of, ID-JAG (same wire as Okta Cross-App Access), RFC 9728 resource metadata, RFC 7523 JWT bearer at resource authorization servers, RFC 9207 issuer identification
Why it differentiates
Issue and consume ID-JAG at governed tool, orchestration, and AI gateway edges; AuthZEN at mint and on each action.
Representative standards
OpenID SSF 1.0, CAEP-aligned Security Event Tokens, RFC 8935 push, RFC 9493 subjects
Why it differentiates
Verified signal → policy → enforcement (push transmit/receive in production).
Representative standards
SCIM 2.0, LDAP v3, virtual directory
Why it differentiates
Configuration-driven connectors and graph-backed membership—not a monolithic identity warehouse.
Representative standards
Model Context Protocol (MCP) incl. 2026-07-28 revision, MCP enterprise-managed authorization (EMA) grant profiles, OAuth 2.1 at the gateway, RFC 8693 delegation narrowing
Why it differentiates
Dual policy enforcement (model traffic + tool calls) with capability without custody—credentials are not returned to the agent.
Representative standards
JWS (RS256), hash-chained receipts, JWKS verification, SCITT-upgradeable receipt format
Why it differentiates
Linked decision → execution → verification chain, not audit logs alone.
The Identity Fabric reference model expects composable, API-first services for all identity types—integrated by policy and orchestration, not shared databases.
| Principle | What to verify |
|---|---|
| API and event parity | Governed actions are available via documented APIs and asynchronous events Security is not UI-only; integrators and agents are first-class callers. |
| Contract integration | Services integrate via APIs and events, not shared databases AuthZEN, SCIM, and LDAP at boundaries; propagation via events. |
| Bring-your-own front door | Existing ITSM, GRC, or IGA portals can drive the same workflows Same authorization contracts for human UI and machine callers. |
| Fail-closed enforcement | Deny when the decision service is unavailable, where policy requires Obligations (step-up MFA, audit) enforced at the Policy Enforcement Point. |
| Explicit maturity | Draft and roadmap items are labeled as such ID-JAG is an implemented IETF draft; FAPI alignment is not formal FAPI certification. |
Front doors (ITSM, GRC, IGA, custom UI, agents) enter via OIDC/OAuth, ID-JAG, and delegation. AuthZEN evaluates across federation and authorization services. SSF/CAEP feeds continuous policy; MCP, SCIM, and LDAP fulfill at the edge; JWS receipts close the proof loop.
Standards inventory
Maturity tags reflect deployment status as of July 28, 2026. Draft and roadmap items are labeled explicitly—see scope statements before RFP reuse.
Identity & Federation Service — OIDC/OAuth-first integration.
| Standard / specification | Platform role | Maturity |
|---|---|---|
| OpenID Connect | SSO and ID tokens | Production |
| OAuth 2.1 | Authorization code, client credentials, token endpoints | Production |
| PKCE (RFC 7636) | Public and native client protection | Production |
| PAR (RFC 9126) | Pushed authorization requests | Production |
| JARM | JWT-secured authorization response | Production |
| private_key_jwt | Confidential client authentication | Production |
| CIBA (OpenID) | Decoupled / out-of-band authentication | Production |
| WebAuthn / FIDO2 | Passkeys; passwordless-capable authentication | Production |
| TOTP | Authenticator-app MFA | Production |
| Temporary Access Pass | Bootstrap and recovery | Production |
| DPoP (RFC 9449) | Sender-constrained tokens Composable with token exchange and ID-JAG | Production |
| Token introspection (RFC 7662) | Resource-server validation | Production |
| JWT / JWS / JWKS | Signing, verification, key rotation | Production |
Appendix
Quick lookup for RFCs, OpenID profiles, and platform roles—searchable for architects and integrators.
25 entries
RFC 7636
PKCE
OAuth public clients
RFC 7662
Token introspection
Resource validation
RFC 7523
JWT bearer grant
ID-JAG Step 2 at resource AS
RFC 8693
OAuth 2.0 Token Exchange
Delegation, OBO, ID-JAG Step 1, agents
RFC 8707
Resource Indicators
Audience binding
RFC 8935
SET Push Delivery
SSF push
RFC 8936
SET Poll Delivery
Roadmap
RFC 9126
PAR
Pushed authorization requests
RFC 9396
RAR
Rich authorization requests
RFC 9449
DPoP
Sender-constrained tokens
RFC 9207
OAuth 2.0 Authorization Server Issuer
Mix-up defence; MCP edge hardening
RFC 9493
Subject identifiers
SSF/CAEP subjects
RFC 9728
Protected Resource Metadata
ID-JAG discovery
OAuth 2.1
OAuth consolidation (IETF)
Platform baseline
OIDC
OpenID Connect
SSO, ID tokens
CIBA
Client Initiated Backchannel Authentication
Decoupled authentication
WebAuthn / FIDO2
W3C / FIDO Alliance
Passkeys
JARM
JWT Secured Authorization Response
Authorization response mode
AuthZEN
OpenID Authorization API
PDP evaluate / search / batch
SSF 1.0
Shared Signals Framework
Continuous access transport
CAEP
Continuous Access Evaluation Profile
Event semantics
SCIM 2.0
System for Cross-domain Identity Management
Provisioning
LDAP v3
Lightweight Directory Access Protocol
Virtual directory
MCP
Model Context Protocol
Agent tools
ID-JAG
Identity Assertion Authorization Grant (IETF draft)
Cross-app access (XAA wire)
Compared with common market patterns—expressed in protocol and proof terms, not marketing slogans.
| Common suite pattern | Identity Fabric pattern | Standards angle |
|---|---|---|
| Monolith with embedded RBAC | Externalized AuthZEN PDP | Open evaluation and search APIs; policies as versioned configuration |
| Overnight batch SoD | Preventive SoD at PDP (milliseconds, fail-closed) | Same engine as application authorization |
| Single relational identity warehouse | Graph + transactional grants + analytics evidence store | LDAP/SCIM at the edge; events for propagation |
| Governance only through vendor UI | Bring-your-own front door + API/event parity | ID-JAG and MCP for non-human callers |
| Agents added later | Agent Governance & Execution on the same spine | MCP, RFC 8693, ID-JAG, Credential Control |
| Common gateway pattern | Fabric pattern | Standards angle |
|---|---|---|
| Tool routing and static API keys | Governed Tool Gateway PEP + AuthZEN per tool | MCP + OAuth + AuthZEN |
| Credentials held in the agent | Capability without custody | Token exchange; secrets not returned to the agent |
| Weak enterprise IGA | Entitlement ledger and access certification engines | SCIM/LDAP fulfillment with proof chain |
| Ad hoc cross-app trust | ID-JAG issue and consume on resource planes | Same IETF draft wire as industry Cross-App Access |
| Foreign agent tokens trusted implicitly | Inbound federation materializes a governed local identity with delegation lineage | RFC 7523 jwt-bearer; foreign JWKS validation, typ gate, replay control, capability ∩ ceiling |
| Identity governed, model runtime ungoverned | Same PEP governs the agent’s model traffic across cloud providers | Kill switch, budget hold, per-turn signed receipt on a verified delegated identity |
Differentiation is composition:
Reference deployments
Mid-2026 baseline metrics—your sizing may differ.
15+
Independently deployable fabric services
115 / 227
AuthZEN application contracts / policies
30+
Event topics in production
176,000+
Dynamic group (ABAC) rules via events
167+ (400+ definitions on full surface)
MCP tools via Governed Tool Gateway
Sub-10 ms
Typical PDP decision latency
Under 5 seconds
Typical search index lag
Read before RFP reuse—accurate claims only.
FAPI
Aligned building blocks and automated tests — not formal OpenID FAPI product certification.
ID-JAG / XAA
IETF draft; interoperable with Okta Cross-App Access wire; issuance production-grade; consumption live-verified with ongoing hardening.
MCP 2026 transport
Governance-first preview slice; the public conformance suite has not been passed—no “MCP 2026 certified”, “passed the official suite”, or “first to” claim is authorized.
MCP EMA
Grant profiles are advertised on protected-resource metadata; two-sided interop with an external IdP/client is not complete—no “EMA certified” claim.
Inbound agent federation
On-behalf-of and autonomous foreign-agent paths are live and hardened; the public trust framework for foreign issuers continues to mature.
SSF
Push transmit/receive in production; poll, RISC, and stream management on roadmap; continuous enforcement scope is expanding.
SoD
Engine production-ready; customer/function catalog content must be populated for turnkey rule libraries.
Access certification
Engine production-ready; production certification campaigns depend on customer rollout.
Privileged access
Governed secrets vault, disclosure, and secretless agent access in production; session recording, shared-account checkout, and rotation automation on roadmap.
Connector catalog
Depth and configuration velocity versus incumbent SKU count—position with evidence, not parity claims.
Decentralized identity / verifiable credentials
Not a current fabric focus; enterprise federation via OIDC (and SAML where deployed).
Agenda for security architects and integration leads.
No. Identity Fabric federates with Okta, Microsoft Entra, and other IdPs. OAuth/OIDC and token exchange let you keep the front door you already operate while centralizing authorization, orchestration, and evidence on the fabric spine.
One PDP evaluates application access, IGA guardrails, SoD, search post-authorization filtering, delegation constraints, and agent tool invocation— with obligations enforced at each Policy Enforcement Point.
ID-JAG answers which application may call which API on whose behalf, using short-lived audience-bound assertions. It is one credential leg; AuthZEN still decides each action at mint and at consumption.
Same protocol family on the wire: ID-JAG is the IETF draft name; XAA is Okta’s product name. EmpowerID implements ID-JAG issuance and consumption and interoperates with XAA-style requests. Okta leads ecosystem distribution; Identity Fabric leads governed authorization depth, delegation, and receipts alongside the workforce IdP—not a connector-count comparison.
No. MCP 2026 transport is a governance-first preview slice on the Governed Tool Gateway; the public conformance suite has not been passed. No “MCP 2026 certified”, “passed the official suite”, or “first to” claim is authorized. Ask any vendor for the test artifact—not the adjective.
No. The platform uses FAPI-aligned building blocks (PAR, DPoP, JARM, private_key_jwt) with automated baseline tests—not a formal OpenID FAPI product certification claim.
Certifications and audit reports are covered on Trust & Compliance surfaces and in sales packages. This standards page focuses on protocol inventory and architecture composition.
This page describes product capabilities as of July 28, 2026. Specifications marked draft or roadmap may change. Metrics are illustrative. Nothing herein modifies a signed agreement.
Online
Powered by EmpowerID AI