%% You should probably cite draft-hardt-xauth-protocol-14 instead of this revision. @techreport{hardt-xauth-protocol-01, number = {draft-hardt-xauth-protocol-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hardt-xauth-protocol/01/}, author = {Dick Hardt}, title = {{The XAuth Protocol}}, pagetotal = 40, year = , month = , day = , abstract = {Client software often desires resources or identity claims that are managed independent of the client. This protocol allows a user and/ or resource owner to delegate resource authorization and/or release of identity claims to an authorization server. Client software can then request access to resources and/or identity claims by calling the authorization server. The authorization server acquires consent and authorization from the user and/or resource owner if required, and then returns the authorization and identity claims that were approved. This protocol can be extended to support alternative client authentication mechanisms, authorizations, claims, and interactions. {[}Editor: suggestions on how to improve this are welcome!{]} {[}Editor: suggestions for other names than XAuth are welcome!{]}}, }