<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.mcguinness-oauth-resource-token-resp" target="https://datatracker.ietf.org/doc/html/draft-mcguinness-oauth-resource-token-resp-02">
   <front>
      <title>OAuth 2.0 Resource Parameter in Access Token Response</title>
      <author initials="K." surname="McGuinness" fullname="Karl McGuinness">
         <organization>Independent</organization>
      </author>
      <author initials="J." surname="Hanson" fullname="Jared Hanson">
         <organization>Keycard Labs</organization>
      </author>
      <date month="March" day="2" year="2026" />
      <abstract>
	 <t>   This specification defines a new parameter resource to be returned in
   OAuth 2.0 access token responses.  It enables clients to confirm that
   the issued token is valid for the intended resource.  This mitigates
   ambiguity and certain classes of security vulnerabilities such as
   resource mix-up attacks, particularly in systems that use the
   Resource Indicators for OAuth 2.0 specification [RFC8707].

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-mcguinness-oauth-resource-token-resp-02" />
   
</reference>
