Skip to content

Pre-release. v0.1 is not out yet, so there is nothing to install and no public source to clone — the quickstart builds from a checkout.

Delegation depth

Every task token names its agent in act, with depth: 1.

RFC 8693 lets act nest, and the specification defines how a chain would look, with the human still in sub. Subact ID does not issue this in v0.1:

{
"sub": "f47ac10b-58cc-4372-a567-0e02b2c3d479",
"act": {
"sub": "agent:db-reader",
"depth": 2,
"act": { "sub": "agent:jira-triage", "depth": 1 }
}
}

The outermost act would be the agent that made the call. The server SDKs still read and limit this shape, as section 9 of the spec requires of every tool server.

On the registration. max_delegation_depth is required on every agent registration and accepts 1 to 5. The control plane checks it on every exchange, against a depth that is always 1 in v0.1, so the value does not change what is issued. Set it to 1.

On the tool server. @subactid/server and @subactid/mcp refuse a token whose act chain is deeper than maxDelegationDepth, which defaults to 1. A deeper token is refused with 403 delegation_too_deep. With tokens from Subact ID v0.1, the default of 1 accepts everything the control plane issues, so leave it unset.

Subact ID Pre-release. v0.1 is not out yet.

© 2026 Nikola Živković PR Agencija za programerske usluge Novi Sad. Subact ID is its product.

LegalTermsPrivacy