@techreport{mora-oauth-entity-profiles-01, number = {draft-mora-oauth-entity-profiles-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-mora-oauth-entity-profiles/01/}, author = {Sreyantha Chary Mora and Pamela Dingle and Karl McGuinness}, title = {{OAuth 2.0 Entity Profiles}}, pagetotal = 36, year = 2026, month = apr, day = 15, abstract = {This specification introduces Entity Profiles as a mechanism to categorize OAuth 2.0 entities—clients and subjects—based on their operational context. Entity Profiles provide structured descriptors for the client initiating the OAuth flow and the subject represented in tokens. This document defines new JWT Claim names and metadata parameters for use in JWTs issued or consumed in OAuth flows, including but not limited to access tokens, ID tokens, JWT authorization grant assertions, and transaction tokens, as well as in token introspection responses, dynamic client registration, and Authorization Server metadata. It also defines vocabulary for classifying acting entities within delegation chains.}, }