Problem
The protocol defers sub-agent token acquisition to bootstrap: "Acquisition of a sub-agent token from the agent provider is platform-dependent and is described in [@?I-D.hardt-aauth-bootstrap], parallel to top-level agent token acquisition" ((#sub-agents)). Bootstrap does not cover it. The pointer dangles.
Suggested direction
Add a sub-agent acquisition section to bootstrap. For the self-hosted case the answer is one paragraph: the operator's self-hosted AP is the parent's AP and self-issues the sub-agent token (sub with the + delimiter, parent_agent claim, fresh cnf key) exactly as it self-issues top-level tokens. The hosted-AP case (parent requests a sub-agent token from its AP) needs its own short pattern.
Context
From the notes.ito.com deployment review (writeup, review pass). Pairs with the many-agents-one-operator issue — same section of bootstrap, same self-issue mechanics.
Problem
The protocol defers sub-agent token acquisition to bootstrap: "Acquisition of a sub-agent token from the agent provider is platform-dependent and is described in [@?I-D.hardt-aauth-bootstrap], parallel to top-level agent token acquisition" ((#sub-agents)). Bootstrap does not cover it. The pointer dangles.
Suggested direction
Add a sub-agent acquisition section to bootstrap. For the self-hosted case the answer is one paragraph: the operator's self-hosted AP is the parent's AP and self-issues the sub-agent token (
subwith the+delimiter,parent_agentclaim, freshcnfkey) exactly as it self-issues top-level tokens. The hosted-AP case (parent requests a sub-agent token from its AP) needs its own short pattern.Context
From the notes.ito.com deployment review (writeup, review pass). Pairs with the many-agents-one-operator issue — same section of bootstrap, same self-issue mechanics.