flâneur

RFC 9700 - Best Current Practice for OAuth 2.0 Security

datatracker.ietf.org · 8,938 words · saved by 1 readers

This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.

RFC 9700 OAuth 2.0 Security BCP January 2025 Lodderstedt, et al. Best Current Practice [Page] Best Current Practice for OAuth 2.0 Security Abstract This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.¶ Status of This Memo This memo…

saved by

related reading