Storing user credentials, forwarding tokens verbatim, or forcing constant re-authentication are the three ways teams get agent delegation wrong. Learn how OAuth 2.0 Token Exchange (RFC 8693) and JWT Bearer assertions (RFC 7523) solve it correctly.