# Token Exchange to delegate access to a subset of resources to a third party

**URL:** <https://forum.keycloak.org/t/token-exchange-to-delegate-access-to-a-subset-of-resources-to-a-third-party/16970>\
**Category:** Getting advice\
**Created:** [August 18, 2022, 10:09am UTC](https://forum.keycloak.org/t/token-exchange-to-delegate-access-to-a-subset-of-resources-to-a-third-party/16970 "2022-08-18T10:09:10Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![sprehn-ero](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sprehn-ero/32/6381_2.png) [@sprehn-ero](https://forum.keycloak.org/u/sprehn-ero)\
**Post date:** [August 18, 2022, 10:09am UTC](https://forum.keycloak.org/t/token-exchange-to-delegate-access-to-a-subset-of-resources-to-a-third-party/16970/1 "2022-08-18T10:09:10Z")

</div>

Hi,  
we are planning to build an “invite” feature to grant 3rd party systems limited access to some of our resources. [OAuth2 Token Exchange](https://www.rfc-editor.org/rfc/rfc8693.html) seems like a promising solution.

When I perform a token exchange still within the same client, KeyCloak responds with a new refresh and access token which include the claims of the subject\_token (realm\_access, resource\_access, etc.).

How can I modify/reduce the scope, realm\_access, resource\_access etc. and add a custom claim with the ID of the resource to the new refresh and access token?

Kind Regards  
Sebastian
