%% You should probably cite draft-ietf-oauth-rfc7523bis-05 instead of this revision. @techreport{ietf-oauth-rfc7523bis-03, number = {draft-ietf-oauth-rfc7523bis-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc7523bis/03/}, author = {Michael B. Jones and Brian Campbell and Chuck Mortimore and Filip Skokan}, title = {{Updates to OAuth 2.0 JSON Web Token (JWT) Client Authentication and Assertion-Based Authorization Grants}}, pagetotal = 14, year = 2025, month = oct, day = 7, abstract = {This specification updates the requirements for audience values in OAuth 2.0 Client Assertion Authentication and Assertion-based Authorization Grants to address a security vulnerability identified in the previous requirements for those audience values in multiple OAuth 2.0 specifications.}, }