%% You should probably cite draft-ietf-oauth-spop instead of this I-D. @techreport{sakimura-oauth-tcse-03, number = {draft-sakimura-oauth-tcse-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sakimura-oauth-tcse/03/}, author = {Nat Sakimura and John Bradley and Naveen Agarwal}, title = {{OAuth Symmetric Proof of Posession for Code Extension}}, pagetotal = 8, year = 2014, month = apr, day = 21, abstract = {The OAuth 2.0 public client utilizing authorization code grant is susceptible to the code interception attack. This specification describe a mechanism that acts as a control against this threat.}, }