<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-oauth-security-topics" target="https://datatracker.ietf.org/doc/html/draft-ietf-oauth-security-topics-29">
   <front>
      <title>OAuth 2.0 Security Best Current Practice</title>
      <author initials="T." surname="Lodderstedt" fullname="Torsten Lodderstedt">
         <organization>SPRIND</organization>
      </author>
      <author initials="J." surname="Bradley" fullname="John Bradley">
         <organization>Yubico</organization>
      </author>
      <author initials="A." surname="Labunets" fullname="Andrey Labunets">
         <organization>Independent Researcher</organization>
      </author>
      <author initials="D." surname="Fett" fullname="Daniel Fett">
         <organization>Authlete</organization>
      </author>
      <date month="June" day="3" year="2024" />
      <abstract>
	 <t>   This document describes best current security practice for OAuth 2.0.
   It updates and extends the threat model and security advice given in
   RFC 6749, RFC 6750, and RFC 6819 to incorporate practical experiences
   gathered since OAuth 2.0 was published and covers new threats
   relevant due to the broader application of OAuth 2.0.  Further, it
   deprecates some modes of operation that are deemed less secure or
   even insecure.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-oauth-security-topics-29" />
   
</reference>
