RFC 9700 - Best Current Practice for OAuth 2.0 Security
This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.
RFC 9700 OAuth 2.0 Security BCP January 2025 Lodderstedt, et al. Best Current Practice [Page] Best Current Practice for OAuth 2.0 Security Abstract This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.¶ Status of This Memo This memo…
saved by
related reading
- RFC 6749: The OAuth 2.0 Authorization Frameworkdatatracker.ietf.org
- Cryptographic right answers | Latacoralatacora.com
- The Letter - Stop Hacklore!hacklore.org
- Why We Don’t Trust the Database With Authentication – Sturdy Statisticsblog.sturdystatistics.com
- Threat actors misuse OAuth applications to automate financially driven attacksmicrosoft.com
- What is OAuth 2.0? Definition & Examples | Auth0auth0.com
- Security incident disclosure — July 2026huggingface.co
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Understanding The Web Security Model, Part III: Basic Principles and the Origin Concepteducatedguesswork.org
- Awareness and Developer Training That Actually Works | Anagram Securityanagramsecurity.com
- Signing in with Google - OAuth 2.0 Simplifiedoauth.com
- webauth:sec10.pdfpdos.csail.mit.edu