@techreport{ietf-oauth-spiffe-client-auth-02, number = {draft-ietf-oauth-spiffe-client-auth-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/02/}, author = {Arndt Schwenkschuster and Pieter Kasselman and Scott Rose and Stian Thorgersen and Nancy Cam-Winget}, title = {{OAuth SPIFFE Client Authentication}}, pagetotal = 25, year = 2026, month = jun, day = 15, abstract = {This specification profiles the Assertion Framework for OAuth 2.0 Client Authentication and Authorization Grants {[}RFC7521{]}, the JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants {[}RFC7523{]}, and OAuth 2.0 Attestation-Based Client Authentication {[}I-D.draft-ietf-oauth-attestation-based-client-auth{]} to enable the use of SPIFFE Verifiable Identity Documents (SVIDs) as client credentials in OAuth 2.0. It defines how OAuth clients with SPIFFE credentials can authenticate to OAuth authorization servers using their JWT-SVIDs, WIT-SVIDs, or X.509-SVIDs without the need for client secrets. This approach enhances security by enabling seamless integration between SPIFFE-enabled workloads and OAuth authorization servers while eliminating the need to distribute and manage shared secrets such as static client secrets.}, }