Minutes IETF125: oauth: Mon 06:00
minutes-125-oauth-202603160600-00
| Meeting Minutes | Web Authorization Protocol (oauth) WG | |
|---|---|---|
| Date and time | 2026-03-16 06:00 | |
| Title | Minutes IETF125: oauth: Mon 06:00 | |
| State | Active | |
| Other versions | markdown | |
| Last updated | 2026-04-06 |
OAuth WG Meeting Minutes - 16.03.2026
Minute takers:
- Hanling wang
- Hannes Tschofenig
OAuth 2.1
John Bradley: Get rid of plain (in chat various people agreed with him)
Kaixuan Luo: Challenge to mandate mix-up mitigation via issuer in the
response alone is not sufficient.
Aaron: Need to provide more guidance.
There are other issues on Github but I wanted to discuss these two.
Client ID Metadata Document
Michael Fraser: We have a similiar situation in the OpenID Federation
scenario. Maybe we can add some guidance.
Brian raises a point about a possible optimization with JWKs
First-Party Apps - Aaron - 10 min
https://datatracker.ietf.org/doc/draft-ietf-oauth-first-party-apps/
Aaron asks for WGLC.
If there is no interest to take actions to incorporate PAR into this
specification then the document is ready for WGLC.
Chairs will issue a WGLC.
Identity Assertion JWT Authorization Grant - Aaron - 10 min
https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant/
Aaron: Do not plan to make any significant changes. Getting close to
WGLC.
Pamela: There is a term in the draft, Cross-App-Access (XAA), which is
not well defined.
Aaron: Will make this more clear.
Volunteer-Reviewers: Justin, Yaron Zehavi, Antoine Fressancourt
Updates to OAuth 2.0 Security Best Current Practice - Kaixuan Luo - 10 min
https://datatracker.ietf.org/doc/draft-ietf-oauth-security-topics-update/
Reviewers: Aaron, Brian
OAuth 2.0 RAR Metadata and Error Signaling - Yaron Zehavi - 10 min
https://datatracker.ietf.org/doc/draft-zehavi-oauth-rar-metadata/
Justin: The discovery issue is challenging. I am excited about this
work.
Pamela: Is there a story for addressing the common schema issue? Has
been discussed?
Yaron: No, this topic has not been discussed.
Aaron: The expression syntax surprised me a bit. There are other ways to
do this in JSON.
Pamela is interested to review the draft.
Direct interaction for native clients using federation - Yaron Zehavi - 10 min
https://datatracker.ietf.org/doc/draft-zehavi-oauth-native-clients-federation/
Reviewers: Antoine Fressancourt, Aaron, Michel Sales
OAuth SPIFFE Client Authentication - Arndt - 10 min
https://www.ietf.org/archive/id/draft-schwenkschuster-oauth-spiffe-client-auth-00.html
Reviewers: Flemming, Brian
Additional Hash Algorithms for OAuth 2.0 PKCE and Proof-of-Possession - Filip - 10 min
https://datatracker.ietf.org/doc/draft-skokan-oauth-additional-hashes/
Reviewers: Mike
OAuth2.0 Extension for Multi-AI Agent Collaboration - Yurong - 10 min
https://datatracker.ietf.org/doc/draft-song-oauth-ai-agent-collaborate-authz/
Reviewers: Aaron
Agent-to-Agent (A2A) Profile for OAuth Transaction Tokens - Chunchi Peter Liu/Yuan Ni - 5 min
https://www.ietf.org/archive/id/draft-liu-oauth-a2a-profile-00.html
Reviewers: Henk, Georg, Yurong Song
Agent Operation Authorization - Dapeng/Suresh - 5 min
https://datatracker.ietf.org/doc/html/draft-liu-agent-operation-authorization-01
Reviewers: Aaron
Policy and Lifecycle Extensions for OAuth Rich Authorization Requests - Meiling - (time permitting)
https://datatracker.ietf.org/doc/draft-chen-oauth-rar-agent-extensions/
https://datatracker.ietf.org/doc/draft-chen-oauth-scope-agent-extensions/
Reviewers: Justin
OAuth 2.0 Scope Aggregation for Multi-Step AI Agent Workflows - Yukuan Jia - (time permitting)
https://datatracker.ietf.org/doc/draft-jia-oauth-scope-aggregation/
Reviewers: