A
AAP
Docs
SpecificationGetting StartedFAQToken Generator
HomeDocumentation

Documentation

Complete documentation for the Agent Authorization Profile. From getting started guides to deep technical specifications.

Quick Access

Quick StartRead SpecView CodeGet Help

Getting Started

Start here

Quick Start Guide

Get up and running with AAP in minutes. Learn the basics and create your first AAP token.

Complete Specification

Full technical specification with formal schemas, semantics, and validation rules.

AI-Optimized

AI Agent Access

Optimized markdown content for AI agents. 99% token reduction via HTTP content negotiation.

Implementation

Reference Implementation

Working Authorization Server and Resource Server implementations in Python.

JSON Schemas

Formal JSON Schema definitions for AAP token validation and interoperability testing.

Test Vectors

70+ test cases covering all specification sections, constraints, and edge cases.

Guides

Migration Guide

Step-by-step guide for migrating from OAuth Scopes to AAP Capabilities.

Deployment Patterns

Kubernetes, Docker, and cloud provider deployment examples and best practices.

FAQ

Frequently asked questions about AAP, security, compliance, and implementation.

Security

Threat Model

Comprehensive threat analysis with 15 attack scenarios and mitigations.

Security Considerations

Cryptographic recommendations, proof-of-possession, and security profiles.

Community & Support

Join the AAP community, contribute to the specification, or get help with implementation.

View on GitHubJoin DiscussionsReport Issues

Agent Authorization Profile

OAuth 2.0 authorization for autonomous AI agents. Built on open standards.

About AAP

  • What is AAP
  • Why AAP
  • How it works
  • Quick Links

Documentation

  • Documentation Hub
  • Getting Started
  • Full Specification
  • AI Agent Access
  • Deployment Guide
  • FAQ
  • Examples

Technical Resources

  • JSON Schemas
  • Test Vectors
  • Token Generator
  • Reference Implementation
  • Migration Guide
  • Threat Model

Community

  • GitHub
  • Discussions
  • Contributing

Standards

  • OAuth 2.0
  • JWT (RFC 7519)
  • Token Exchange (RFC 8693)
  • DPoP

© 2026 Agent Authorization Profile. Built on OAuth 2.0, JWT, and open standards.

GitHubIETF