Okta and Microsoft's competing SCIM-agent drafts have been consolidated into one informational draft, draft-wzdk-scim-agent-resource-00. The working-group line: SCIM provisions the right to an agent identity — lifecycle — not the runtime credential. Model agents as first-class principals now; do not wait for the RFC, and do not overload SCIM into authorization.

What WorkOS Published

On September 30, 2026, WorkOS published SCIM for AI, one year later. A year after two competing IETF drafts, the companies behind them are writing one document together.

In October 2025, Okta's Abbey / Cohen draft modeled agents as related to an "agentic application" (owned, authorized, or guest). Microsoft's Wahl draft treated the agent as its own first-class resource. By IETF 125 in March 2026, that split had become a named consolidation agenda item.

The Consolidated Draft

draft-wzdk-scim-agent-resource-00, published June 2026, is co-authored by M. Wahl and P. Dingle of Microsoft, D. Zollner of Okta, and I. Kazzouzi of Nextident. Status: informational, expires December 2026.

WorkOS restates the working group's sharper line: SCIM provisions the right to an identity, not the identity credential itself. SPIFFE (and OAuth) issue the actual credential after a workload proves it matches what it claims to be. Federation, under the emerging model, is bilateral and human-authorized: federated domains share agent identities via SCIM; non-federated domains do not see them.

The draft keeps SCIM's core lifecycle — a client can update and remove the agent record and associate it with groups, roles, and entitlements — rather than inventing a parallel system.

What To Do Now

WorkOS is direct: nothing here is stable enough to build against yet.

  • Model agent identities as their own resource with clear lifecycle hooks — the direction the consolidated draft is trending — rather than betting on the application-centric shape from the earlier Okta draft.
  • Keep runtime auth on short-lived tokens (OAuth / workload identity). Do not expect SCIM to issue or attenuate those credentials.
  • Check back around the December 2026 expiry to see whether the draft is renewed, replaced, or promoted.

What The Post Does Not Prove

  • Informational status is not standards-track. WorkOS says not to build against any single draft prematurely.
  • An illustrative JSON shape in the post is labeled as illustrative of the discussion, not a spec quotation.
  • This extends credential-architecture and Airlock identity notes. It does not replace them.

Related: See our notes on the AI agent permissions checklist and the Agent Identity and Know-Your-Agent playbook.