<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.kasselman-oauth-spiffe" target="https://datatracker.ietf.org/doc/html/draft-kasselman-oauth-spiffe-01">
   <front>
      <title>OAuth Client Registration on First Use with SPIFFE</title>
      <author initials="P." surname="Kasselman" fullname="Pieter Kasselman">
         <organization>SPIRL</organization>
      </author>
      <author initials="D." surname="Sneeggen" fullname="Dag Sneeggen">
         <organization>Signicat</organization>
      </author>
      <date month="June" day="24" year="2025" />
      <abstract>
	 <t>   The OAuth framework is a widely deployed authorization protocol
   standard that enables applications to obtain limited access to user
   resources.  OAuth clients must be registered with the OAuth
   authorization server, which poses significant operational challenges
   in dynamically scaling environments.  The Secure Production Identity
   Framework For Everyone (SPIFFE) is a graduated Cloud Native Compute
   Foundation project designed to dynamically attest and verify workload
   identity.  This draft describes how workloads with SPIFFE credentials
   can be used with OAuth to lessen the operational burden of client
   registration through a &quot;register on first use&quot; principle.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-kasselman-oauth-spiffe-01" />
   
</reference>
