Okta and Microsoft's competing SCIM-agent drafts have been consolidated into one informational draft, draft-wzdk-scim-agent-resource-00. The working-group line: SCIM provisions the right to an agent identity — lifecycle — not the runtime credential. Model agents as first-class principals now; do not wait for the RFC, and do not overload SCIM into authorization.
What WorkOS Published
On September 30, 2026, WorkOS published SCIM for AI, one year later. A year after two competing IETF drafts, the companies behind them are writing one document together.
In October 2025, Okta's Abbey / Cohen draft modeled agents as related to an "agentic application" (owned, authorized, or guest). Microsoft's Wahl draft treated the agent as its own first-class resource. By IETF 125 in March 2026, that split had become a named consolidation agenda item.
The Consolidated Draft
draft-wzdk-scim-agent-resource-00, published June 2026, is co-authored by M. Wahl and P. Dingle of Microsoft, D. Zollner of Okta, and I. Kazzouzi of Nextident. Status: informational, expires December 2026.
WorkOS restates the working group's sharper line: SCIM provisions the right to an identity, not the identity credential itself. SPIFFE (and OAuth) issue the actual credential after a workload proves it matches what it claims to be. Federation, under the emerging model, is bilateral and human-authorized: federated domains share agent identities via SCIM; non-federated domains do not see them.
The draft keeps SCIM's core lifecycle — a client can update and remove the agent record and associate it with groups, roles, and entitlements — rather than inventing a parallel system.
What To Do Now
WorkOS is direct: nothing here is stable enough to build against yet.
- Model agent identities as their own resource with clear lifecycle hooks — the direction the consolidated draft is trending — rather than betting on the application-centric shape from the earlier Okta draft.
- Keep runtime auth on short-lived tokens (OAuth / workload identity). Do not expect SCIM to issue or attenuate those credentials.
- Check back around the December 2026 expiry to see whether the draft is renewed, replaced, or promoted.
What The Post Does Not Prove
- Informational status is not standards-track. WorkOS says not to build against any single draft prematurely.
- An illustrative JSON shape in the post is labeled as illustrative of the discussion, not a spec quotation.
- This extends credential-architecture and Airlock identity notes. It does not replace them.
Related: See our notes on the AI agent permissions checklist and the Agent Identity and Know-Your-Agent playbook.