Skip to main content

Web Authorization Protocol (oauth)

Document Date Status IPR AD/Shepherd
Active Internet-Drafts (11 hits)
51 pages
draft-ietf-oauth-attestation-based-client-auth-11
OAuth 2.0 Attestation-Based Client Authentication
2026-09-03
I-D Exists
In WG Last Call

Hannes Tschofenig
20 pages
draft-ietf-oauth-client-id-metadata-document-02
OAuth Client ID Metadata Document
2026-07-06
I-D Exists
WG Document

38 pages 2026-09-16
New
I-D Exists
WG Document

41 pages
draft-ietf-oauth-first-party-apps-04
OAuth 2.0 for First-Party Applications
2026-07-01
I-D Exists
WG Consensus: Waiting for Write-Up

Hannes Tschofenig
65 pages
draft-ietf-oauth-identity-assertion-authz-grant-04
Identity Assertion JWT Authorization Grant
2026-05-21
I-D Exists
WG Document

27 pages
draft-ietf-oauth-rar-metadata-remediation-00
OAuth 2.0 RAR Metadata and Error Remediation
2026-08-23
I-D Exists
WG Document

12 pages
draft-ietf-oauth-refresh-token-expiration-03
OAuth 2.0 Refresh Token and Authorization Expiration
2026-07-06
I-D Exists
WG Document

29 pages
draft-ietf-oauth-security-topics-update-03
Updates to OAuth 2.0 Security Best Current Practice
2026-07-05
I-D Exists
WG Document

25 pages
draft-ietf-oauth-spiffe-client-auth-02
OAuth SPIFFE Client Authentication
2026-06-15
I-D Exists
WG Document

38 pages 2026-07-30
I-D Exists
WG Consensus: Waiting for Write-Up
Dec 2026

Rifaat Shekh-Yusef
103 pages
draft-ietf-oauth-v2-1-16
The OAuth 2.1 Authorization Framework
2026-09-02
I-D Exists
WG Document
Dec 2026

Active with the IESG Internet-Drafts (5 hits)
29 pages
draft-ietf-oauth-identity-chaining-17
OAuth Identity and Authorization Chaining Across Domains
2026-07-19
IESG: RFC Ed Queue 97
RFC Editor: Awaiting First editor
Submitted to IESG for Publication : Proposed Standard
Reviews: secdir IETF Last Call opsdir IETF Last Call genart IETF Last Call artart IETF Last Call
Deb Cooley
Rifaat Shekh-Yusef
16 pages
draft-ietf-oauth-rfc7523bis-11
Updates to OAuth 2.0 JSON Web Token (JWT) Client Authentication and Assertion-Based Authorization Grants
2026-04-28
IESG: RFC Ed Queue 146
RFC Editor: Awaiting Second editor
Submitted to IESG for Publication : Proposed Standard
Reviews: secdir IETF Last Call opsdir IETF Last Call artart IETF Last Call genart IETF Last Call
Deb Cooley
Rifaat Shekh-Yusef
25 pages
draft-ietf-oauth-rfc8725bis-10
JSON Web Token Best Current Practices
2026-08-21
IESG: RFC Ed Queue
RFC Editor: blocked: Reference Not Received
Submitted to IESG for Publication : Best Current Practice
Reviews: genart IETF Last Call artart secdir IETF Last Call artart IETF Last Call
Deb Cooley
Hannes Tschofenig
74 pages
draft-ietf-oauth-sd-jwt-vc-19
SD-JWT-based Verifiable Digital Credentials (SD-JWT VC)
2026-08-31
Waiting for AD Go-Ahead
Submitted to IESG for Publication : Proposed Standard
Reviews: secdir IETF Last Call artart IETF Last Call genart IETF Last Call httpdir Early
Jul 2026
Action Holder: Deb Cooley
Deb Cooley
Hannes Tschofenig
80 pages
draft-ietf-oauth-status-list-21
Token Status List (TSL)
2026-06-21
IESG: RFC Ed Queue 115
RFC Editor: Awaiting First editor
Submitted to IESG for Publication : Proposed Standard
Reviews: artart IETF Last Call genart IETF Last Call
Deb Cooley
Rifaat Shekh-Yusef
Expired Internet-Drafts (10 hits)
7 pages
draft-ietf-oauth-closing-redirectors-00
OAuth 2.0 Security: Closing Open Redirectors in OAuth
2016-02-04
Expired
WG Document : Best Current Practice

9 pages 2018-10-19
Expired
WG Document

11 pages
draft-ietf-oauth-incremental-authz-04
OAuth 2.0 Incremental Authorization
2020-05-03
Expired
WG Document

14 pages
draft-ietf-oauth-mix-up-mitigation-01
OAuth 2.0 Mix-Up Mitigation
2016-07-07
Expired
WG Document

23 pages
draft-ietf-oauth-pop-architecture-08
OAuth 2.0 Proof-of-Possession (PoP) Security Architecture
2016-07-08
Expired
Submitted to IESG for Publication : Informational
Reviews: opsdir IETF Last Call opsdir IETF Last Call genart genart secdir
Kathleen Moriarty
Kepeng Li
17 pages
draft-ietf-oauth-pop-key-distribution-07
OAuth 2.0 Proof-of-Possession: Authorization Server to Client Key Distribution
2019-03-27
Expired
WG Document : Proposed Standard

Kepeng Li
8 pages 2019-08-01
Expired
In WG Last Call

Rifaat Shekh-Yusef
13 pages
draft-ietf-oauth-signed-http-request-03
A Method for Signing HTTP Requests for OAuth
2016-08-08
Expired
WG Document

30 pages
draft-ietf-oauth-token-binding-08
OAuth 2.0 Token Binding
2018-10-19
Expired
WG Document

37 pages
draft-ietf-oauth-v2-http-mac-05
OAuth 2.0 Message Authentication Code (MAC) Tokens
2014-01-15
Expired
WG Document

Barry Leiba
RFCs (36 hits)
76 pages
RFC 6749
The OAuth 2.0 Authorization Framework Errata
2012-10
Proposed Standard RFC
Updated by rfc8252, rfc8996, rfc9700
4 Stephen Farrell
18 pages
RFC 6750
The OAuth 2.0 Authorization Framework: Bearer Token Usage Errata
2012-10
Proposed Standard RFC
Updated by rfc8996, rfc9700
2 Stephen Farrell
5 pages
RFC 6755
An IETF URN Sub-Namespace for OAuth
2012-10
Informational RFC
Stephen Farrell
71 pages
RFC 6819
OAuth 2.0 Threat Model and Security Considerations Errata
2013-01
Informational RFC
Updated by rfc9700
Stephen Farrell
11 pages
RFC 7009
OAuth 2.0 Token Revocation Errata
2013-08
Proposed Standard RFC
Stephen Farrell
30 pages
RFC 7519
JSON Web Token (JWT) Errata
2015-05
Proposed Standard RFC
Updated by rfc7797, rfc8725
Kathleen Moriarty
20 pages
RFC 7521
Assertion Framework for OAuth 2.0 Client Authentication and Authorization Grants
2015-05
Proposed Standard RFC
Kathleen Moriarty
15 pages
RFC 7522
Security Assertion Markup Language (SAML) 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants
2015-05
Proposed Standard RFC
Kathleen Moriarty
12 pages
RFC 7523
JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants
2015-05
Proposed Standard RFC
Kathleen Moriarty
39 pages
RFC 7591
OAuth 2.0 Dynamic Client Registration Protocol Errata
2015-07
Proposed Standard RFC
Kathleen Moriarty
18 pages
RFC 7592
OAuth 2.0 Dynamic Client Registration Management Protocol
2015-07
Experimental RFC
Kathleen Moriarty
20 pages
RFC 7636
Proof Key for Code Exchange by OAuth Public Clients Errata
2015-09
Proposed Standard RFC
Kathleen Moriarty
17 pages
RFC 7662
OAuth 2.0 Token Introspection Errata
2015-10
Proposed Standard RFC
Kathleen Moriarty
15 pages
RFC 7800
Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs) Errata
2016-04
Proposed Standard RFC
Kathleen Moriarty
15 pages
RFC 8176
Authentication Method Reference Values
2017-06
Proposed Standard RFC
Kathleen Moriarty
21 pages
RFC 8252
OAuth 2.0 for Native Apps Errata
2017-10
Best Current Practice RFC
Part of BCP 212
Kathleen Moriarty
23 pages
RFC 8414
OAuth 2.0 Authorization Server Metadata Errata
2018-06
Proposed Standard RFC
Eric Rescorla
21 pages
RFC 8628
OAuth 2.0 Device Authorization Grant Errata
2019-08
Proposed Standard RFC
Roman Danyliw
27 pages
RFC 8693
OAuth 2.0 Token Exchange Errata
2020-01
Proposed Standard RFC
Roman Danyliw
24 pages
RFC 8705
OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens
2020-02
Proposed Standard RFC
Roman Danyliw
11 pages
RFC 8707
Resource Indicators for OAuth 2.0 Errata
2020-02
Proposed Standard RFC
Roman Danyliw
13 pages
RFC 8725
JSON Web Token Best Current Practices
2020-02
Best Current Practice RFC
Also known as BCP 225
Roman Danyliw
15 pages
RFC 9068
JSON Web Token (JWT) Profile for OAuth 2.0 Access Tokens Errata
2021-10
Proposed Standard RFC
Roman Danyliw
25 pages
RFC 9101
The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR)
2021-08
Proposed Standard RFC
Roman Danyliw
18 pages
RFC 9126
OAuth 2.0 Pushed Authorization Requests Errata
2021-09
Proposed Standard RFC
Roman Danyliw
9 pages
RFC 9207
OAuth 2.0 Authorization Server Issuer Identification
2022-03
Proposed Standard RFC
Roman Danyliw
6 pages
RFC 9278
JWK Thumbprint URI
2022-08
Proposed Standard RFC
Roman Danyliw
38 pages
RFC 9396
OAuth 2.0 Rich Authorization Requests
2023-05
Proposed Standard RFC
Roman Danyliw
39 pages
RFC 9449
OAuth 2.0 Demonstrating Proof of Possession (DPoP) Errata
2023-09
Proposed Standard RFC
Roman Danyliw
14 pages
RFC 9470
OAuth 2.0 Step Up Authentication Challenge Protocol Errata
2023-09
Proposed Standard RFC
Roman Danyliw
46 pages
RFC 9700
Best Current Practice for OAuth 2.0 Security
2025-01
Best Current Practice RFC
Also known as BCP 240
Roman Danyliw
13 pages
RFC 9701
JSON Web Token (JWT) Response for OAuth Token Introspection
2025-01
Proposed Standard RFC
Roman Danyliw
25 pages
RFC 9728
OAuth 2.0 Protected Resource Metadata
2025-04
Proposed Standard RFC
Deb Cooley
88 pages
RFC 9901
Selective Disclosure for JSON Web Tokens
2025-11
Proposed Standard RFC
Deb Cooley
49 pages
RFC 10017
OAuth 2.0 for Browser-Based Applications
2026-08
Best Current Practice RFC
Part of BCP 212
Deb Cooley
50 pages
RFC 10027
Best Current Practice for Security of Cross-Device Flows
2026-08
Best Current Practice RFC
Also known as BCP 247
Deb Cooley
Related Internet-Drafts and RFCs (73 hits)
14 pages
draft-agnihotri-oauth-agent-impl-status-02
Implementation Status of OAuth Identity Chaining and Transaction Tokens
2026-06-23
I-D Exists

47 pages
draft-ambekar-oauth-epop-03
JSON Web Token (JWT) Profile for OAuth 2.0 Enveloped Proof of Possession (EPOP)
2026-07-23
I-D Exists

32 pages 2026-05-21
I-D Exists

26 pages
draft-araut-oauth-transactiontokens-bcp-00
OAuth Transaction Tokens Best Current Practice
2026-07-19
I-D Exists

15 pages
draft-aravind-oauth-decision-subject-00
Decision-Subject Representation for Agent Authorization
2026-07-19
I-D Exists

12 pages
draft-aravind-oauth-operator-of-record-00
Operator-of-Record: an Origination Marker for Agent-Operated Presentations and Decisions
2026-07-19
I-D Exists

6 pages
draft-bandyopadhayaya-oauth-ciba-push-binding-00
CIBA Binding for OAuth Push-Based Authentication Device Discovery
2026-07-29
I-D Exists

21 pages
draft-bandyopadhayaya-oauth-push-device-00
Discovery and Device Lifecycle for OAuth Push-Based Authentication
2026-07-29
I-D Exists

40 pages
draft-chen-oauth-agent-authz-use-cases-03
Agent Authorization use cases and gap analysis
2026-08-25
I-D Exists

9 pages
draft-chen-oauth-agent-revocation-00
OAuth 2.0 Agent Authorization Explicit Revocation
2026-04-27
I-D Exists

11 pages
draft-chen-oauth-rar-agent-extensions-01
Policy, Lifecycle, and Intent Extensions for OAuth Rich Authorization Requests
2026-04-21
I-D Exists

15 pages
draft-chen-oauth-roadmap-01
A Comprehensive Roadmap for OAuth 2.0 Standards and Drafts
2026-05-06
I-D Exists

30 pages
draft-chu-oauth-subject-key-binding-00
OAuth Subject Signing Key Binding for Resource Servers
2026-09-01
I-D Exists

14 pages
draft-coetzee-oauth-spt-txn-tokens-03
Transaction-Bound Authorization Tokens for Software and AI Agents (SPT-Txn)
2026-07-19
I-D Exists

26 pages
draft-dellaert-oauth-approval-based-dcr-00
OAuth 2.0 Approval-Based Dynamic Client Registration
2026-07-19
I-D Exists

26 pages
draft-ekahraman-oauth-attestation-authz-native-app-01
OAuth 2.0 Attestation Based Authorization for Native Applications
2026-08-20
I-D Exists

17 pages
draft-embesozzi-oauth-agent-native-authorization-00
OAuth 2.0 Agents Native Authorization via Structured Elicitation
2026-04-03
Expires soon
I-D Exists

11 pages
draft-emerson-oauth-user-mediated-delivery-00
User-Mediated Credential Delivery as a Complementary Authorization Primitive for AI Agents
2026-07-01
I-D Exists
1
31 pages
draft-fletcher-oauth-txn-token-chaining-profile-00
Transaction Token Authorization Grant Profile for OAuth Identity and Authorization Chaining
2026-09-10
I-D Exists

24 pages
draft-gazitt-oauth-authzen-claims-01
AuthZEN Profile for Authorization Claims in JWT Access Tokens
2026-09-01
I-D Exists

49 pages
draft-gazitt-oauth-authzen-issuance-01
AuthZEN Profile for OAuth 2.0 Token Issuance
2026-09-01
I-D Exists

26 pages
draft-gazitt-oauth-authzen-token-exchange-01
AuthZEN Binding for OAuth 2.0 Token Exchange
2026-09-01
I-D Exists

15 pages 2026-04-21
I-D Exists

34 pages
draft-hamr-oauth-agent-delegation-02
An Attenuated Delegation Profile for Automated Agents
2026-09-20
New
I-D Exists

164 pages 2026-09-25
New
I-D Exists

25 pages 2026-07-04
I-D Exists

15 pages
draft-jia-oauth-scope-aggregation-01
OAuth 2.0 Scope Aggregation for Multi-Step AI Agent Workflows
2026-08-14
I-D Exists

17 pages
draft-jiang-oauth-intent-admission-00
Intent Admission Assertions for Agentic Systems
2026-06-23
I-D Exists

13 pages 2026-05-19
I-D Exists

19 pages
draft-kemp-oauth-x509-bearer-00
X.509 Certificate Bearer Profile for OAuth 2.0 Client Authentication and Authorization Grants
2026-09-02
I-D Exists

62 pages
draft-li-oauth-delegated-authorization-03
OAuth 2.0 Delegated Authorization
2026-07-24
I-D Exists

43 pages
draft-li-oauth-policy-based-anonymous-tokens-00
OAuth 2.0 Policy-Based Anonymous Access Tokens
2026-08-26
I-D Exists

23 pages
draft-liu-oauth-authorization-evidence-01
Authorization Evidence and Audit Trail for OAuth 2.0 Access Tokens
2026-06-22
I-D Exists

46 pages
draft-liu-oauth-chain-delegation-00
Delegation Chain for OAuth 2.0
2026-06-07
I-D Exists

20 pages
draft-liu-oauth-cross-domain-txn-token-00
Cross-domain Transaction Tokens
2026-07-03
I-D Exists

34 pages
draft-liu-oauth-rego-policy-00
Rego Policy Language for OAuth 2.0 Authorization
2026-06-12
I-D Exists

111 pages
draft-mcguinness-oauth-actor-profile-00
OAuth Actor Profile for Delegation
2026-04-30
I-D Exists

57 pages
draft-mcguinness-oauth-actor-proofs-00
OAuth Actor-Signed Hop Proofs
2026-07-04
I-D Exists

61 pages
draft-mcguinness-oauth-actor-receipts-00
OAuth Actor Receipts for Delegation Provenance
2026-07-04
I-D Exists

32 pages
draft-mcguinness-oauth-ai-agent-instance-00
OAuth 2.0 AI Agent Instance Profile
2026-07-04
I-D Exists

78 pages
draft-mcguinness-oauth-client-instance-assertion-01
OAuth 2.0 Client Instance Assertion
2026-06-24
I-D Exists

50 pages
draft-mcguinness-oauth-domain-authorized-issuer-00
OAuth Domain-Authorized Issuer Trust Method
2026-07-05
I-D Exists

58 pages
draft-mcguinness-oauth-id-assertion-framework-00
OAuth Identity Assertion Trust Framework
2026-07-05
I-D Exists

84 pages
draft-mcguinness-oauth-id-continuation-assertion-02
Identity Continuation Assertion for OAuth 2.0 Token Exchange
2026-09-08
I-D Exists

35 pages
draft-mcguinness-oauth-insufficient-claims-00
OAuth 2.0 Insufficient Claims Challenge
2026-05-27
I-D Exists

77 pages
draft-mcguinness-oauth-mission-00
Mission-Bound Authorization for OAuth 2.0
2026-07-06
I-D Exists

11 pages
draft-mcguinness-oauth-token-exchange-cnf-00
Confirmation Response Parameter for OAuth 2.0 Token Exchange
2026-07-18
I-D Exists

19 pages
draft-mishra-oauth-agent-grants-02
OAuth Profile for Delegated AI Agent Authorization
2026-08-30
I-D Exists

36 pages
draft-mora-oauth-entity-profiles-01
OAuth 2.0 Entity Profiles
2026-04-15
I-D Exists

16 pages
draft-moros-oauth-browser-session-handoff-00
Browser Session Establishment Using OAuth 2.0 Token Exchange and Short-Lived Authorization Codes
2026-04-16
I-D Exists

109 pages
draft-mw-oauth-actor-chain-01
Cryptographically Verifiable Actor Chains for OAuth 2.0 Token Exchange
2026-06-15
I-D Exists

45 pages
draft-mw-oauth-tls-session-bound-tokens-07
TLS-Session-Bound Access Tokens for OAuth 2.0
2026-06-20
I-D Exists

23 pages 2026-07-03
I-D Exists

66 pages
draft-niyikiza-oauth-attenuating-agent-tokens-01
Attenuating Authorization Tokens for Agentic Delegation Chains
2026-06-15
I-D Exists

12 pages 2026-07-24
I-D Exists

23 pages
draft-richer-oauth-httpsig-03
OAuth Proof of Possession Tokens with HTTP Message Signatures
2026-07-28
I-D Exists

3 pages
draft-rosomakho-oauth-txn-challange-00
Placeholder for typoed email alias
2026-06-25
I-D Exists

33 pages
draft-rosomakho-oauth-txn-challenge-00
OAuth Transaction Authorization Challenge
2026-06-25
I-D Exists

70 pages
draft-sharma-oauth-identity-propagation-context-01
Identity Propagation Context for Multi-Hop Delegation in OAuth 2.0 Environments
2026-07-23
I-D Exists

9 pages
draft-skyfire-oauth-aml-methods-00
Anti-Money Laundering Methods Values
2026-07-18
I-D Exists

8 pages
draft-skyfire-oauth-amr-values-01
Additional Authentication Method Reference Values
2026-07-19
I-D Exists

10 pages
draft-skyfire-oauth-id-verification-01
Identity Verification Methods Values
2026-07-19
I-D Exists

27 pages 2026-07-19
I-D Exists

8 pages 2026-07-19
I-D Exists

30 pages 2026-07-19
I-D Exists

17 pages
draft-song-oauth-ai-agent-collaborate-authz-02
OAuth2.0 Extension for Multi-AI Agent Collaboration
2026-06-30
I-D Exists

44 pages
draft-valverde-oauth-pact-00
PACT: Private Agent Consent and Trust Profile for OAuth 2.1 and CIBA
2026-04-18
I-D Exists

24 pages
draft-valverde-oauth-veil-00
VEIL: Verified Ephemeral Identity Layer for OAuth 2.1
2026-04-18
I-D Exists

20 pages
draft-vicente-oauth-apm-05
Authorization Posture Mechanism (APM): Per-Transaction Consistency for OAuth 2.0
2026-09-12
I-D Exists

12 pages
draft-watts-oauth-agent-revocation-closure-00
Revocation Closure for Agentic Authorization Systems
2026-09-13
I-D Exists

23 pages
draft-winmagic-oauth-condition-bound-keys-00
Condition-Bound Keys for Mutual-TLS Client Authentication and DPoP
2026-08-12
I-D Exists

43 pages
draft-zehavi-oauth-authz-req-del-chain-01
OAuth Authorization Request Delegation Chain
2026-09-10
I-D Exists

23 pages
draft-zhu-oauth-async-delegation-05
Delegated Refresh Tokens for OAuth 2.0 Token Exchange
2026-08-03
I-D Exists