Delegated User Identity
Can a caller obtain a token scoped to the HUMAN it is acting for, or only a credential belonging to the integration itself? Section 10.3 of draft-klrc-aiagent-auth-00 splits exactly this way — the user delegates authorization, versus the agent obtains its own — and nothing in this rubric distinguished them. It is the difference between an audit log that can name a delegated subject and one that cannot, which Section 11 of that draft makes a MUST. DISTINCT FROM `auth_clarity` on purpose. A provider can hold strong bound credentials and still offer no delegation path, and the reverse is equally possible; scoring them as one dimension would let a strong answer to one question hide a missing answer to the other. MEASURED BEFORE IT WAS BUILT: 768 providers declare `authorizationCode`, ~67% of the 1,142 declaring any oauth2 and 20x the `openIdConnect` population. That discriminating power is what separates it from `agent_identity_declared`, which stays parked at 13 providers. ADDED AT SLOT 16, APPENDED. Dimension order is positional in DIM_ORDER and in the glyph; appending shifts nothing, inserting would shift every slot after it.
How it is scored
One signal, read from what the provider publishes, worth 6 points of the 139 in the agent-readiness score.
| Signal the scorer reads | Points |
|---|---|
a served discovery document listing authorization_code in grant_types_supported (served), else an oauth2 authorizationCode flow or openIdConnect declared in an OpenAPI (documented) | 6 |
Grades and what each earns
This dimension is graded rather than pass/fail: how the signal was evidenced decides what fraction of the points it earns.
| Grade | Credit | Points | Providers |
|---|---|---|---|
| served | 1.0× | 6.0 | 1,286 |
| documented | 0.5× | 3.0 | 647 |
Top providers
The top 500 of 1,933 providers publishing this signal, ranked by credit earned, ties broken by composite.
The other 18 dimensions
github.com/api-evangelist/<provider>, and each check above names the exact artifact it
reads. Publish the artifact, open a pull request, and the next scoring run picks it up — no gatekeeping
and no fee. The full rubric is at apis.io/rating/, and
prioritized profiling
is the fast lane if you would rather have it done for you.
Scored on rubric v0.17.2 across 27,504 providers · lists rebuilt 2026-09-01 · capped at the top 500 per page.