@techreport{ietf-oauth-attestation-based-client-auth-10, number = {draft-ietf-oauth-attestation-based-client-auth-10}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-attestation-based-client-auth/10/}, author = {Tobias Looker and Paul Bastian and Christian Bormann}, title = {{OAuth 2.0 Attestation-Based Client Authentication}}, pagetotal = 43, year = 2026, month = jul, day = 6, abstract = {This specification defines an extension to the OAuth 2.0 protocol (RFC 6749) that enables a client instance to include a key-bound attestation when interacting with an Authorization Server or Resource Server. This mechanism allows a client instance to prove its authenticity verified by a client attester without revealing its target audience to that attester. It may also serve as a mechanism for client authentication as per OAuth 2.0.}, }