Skip to main content

Minutes IETF125: oauth: Mon 06:00
minutes-125-oauth-202603160600-00

Meeting Minutes Web Authorization Protocol (oauth) WG
Date and time 2026-03-16 06:00
Title Minutes IETF125: oauth: Mon 06:00
State Active
Other versions markdown
Last updated 2026-04-06

minutes-125-oauth-202603160600-00

OAuth WG Meeting Minutes - 16.03.2026

Minute takers:

  • Hanling wang
  • Hannes Tschofenig

OAuth 2.1

John Bradley: Get rid of plain (in chat various people agreed with him)

Kaixuan Luo: Challenge to mandate mix-up mitigation via issuer in the
response alone is not sufficient.

Aaron: Need to provide more guidance.

There are other issues on Github but I wanted to discuss these two.

Client ID Metadata Document

Michael Fraser: We have a similiar situation in the OpenID Federation
scenario. Maybe we can add some guidance.

Brian raises a point about a possible optimization with JWKs

First-Party Apps - Aaron - 10 min

https://datatracker.ietf.org/doc/draft-ietf-oauth-first-party-apps/

Aaron asks for WGLC.

If there is no interest to take actions to incorporate PAR into this
specification then the document is ready for WGLC.

Chairs will issue a WGLC.

Identity Assertion JWT Authorization Grant - Aaron - 10 min

https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant/

Aaron: Do not plan to make any significant changes. Getting close to
WGLC.

Pamela: There is a term in the draft, Cross-App-Access (XAA), which is
not well defined.

Aaron: Will make this more clear.

Volunteer-Reviewers: Justin, Yaron Zehavi, Antoine Fressancourt

Updates to OAuth 2.0 Security Best Current Practice - Kaixuan Luo - 10 min

https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics-update/

Reviewers: Aaron, Brian

OAuth 2.0 RAR Metadata and Error Signaling - Yaron Zehavi - 10 min

https://datatracker.ietf.org/doc/draft-zehavi-oauth-rar-metadata/

Justin: The discovery issue is challenging. I am excited about this
work.

Pamela: Is there a story for addressing the common schema issue? Has
been discussed?

Yaron: No, this topic has not been discussed.

Aaron: The expression syntax surprised me a bit. There are other ways to
do this in JSON.

Pamela is interested to review the draft.

Direct interaction for native clients using federation - Yaron Zehavi - 10 min

https://datatracker.ietf.org/doc/draft-zehavi-oauth-native-clients-federation/

Reviewers: Antoine Fressancourt, Aaron, Michel Sales

OAuth SPIFFE Client Authentication - Arndt - 10 min

https://www.ietf.org/archive/id/draft-schwenkschuster-oauth-spiffe-client-auth-00.html

Reviewers: Flemming, Brian

Additional Hash Algorithms for OAuth 2.0 PKCE and Proof-of-Possession - Filip - 10 min

https://datatracker.ietf.org/doc/draft-skokan-oauth-additional-hashes/

Reviewers: Mike

OAuth2.0 Extension for Multi-AI Agent Collaboration - Yurong - 10 min

https://datatracker.ietf.org/doc/draft-song-oauth-ai-agent-collaborate-authz/

Reviewers: Aaron

Agent-to-Agent (A2A) Profile for OAuth Transaction Tokens - Chunchi Peter Liu/Yuan Ni - 5 min

https://www.ietf.org/archive/id/draft-liu-oauth-a2a-profile-00.html

Reviewers: Henk, Georg, Yurong Song

Agent Operation Authorization - Dapeng/Suresh - 5 min

https://datatracker.ietf.org/doc/html/draft-liu-agent-operation-authorization-01

Reviewers: Aaron

Policy and Lifecycle Extensions for OAuth Rich Authorization Requests - Meiling - (time permitting)

https://datatracker.ietf.org/doc/draft-chen-oauth-rar-agent-extensions/

https://datatracker.ietf.org/doc/draft-chen-oauth-scope-agent-extensions/

Reviewers: Justin

OAuth 2.0 Scope Aggregation for Multi-Step AI Agent Workflows - Yukuan Jia - (time permitting)

https://datatracker.ietf.org/doc/draft-jia-oauth-scope-aggregation/

Reviewers: