I'll also add that something like refresh_token_scope would be useful for the (expired) draft https://datatracker.ietf.org/doc/html/draft-ietf-oauth-incremental-authz-04 which Google implemented, as it means that there can be more scopes in the refresh token than were explicitly requested in the initial authorization code flow request. (Aside: I'd also be happy to revive draft-ietf-oauth-incremental-authz if there's interest.)
On Fri, Jul 24, 2026 at 4:32 AM Nick Watson <[email protected]> wrote: > +1 refresh_token_scope seems like a quick win that we can slot in amongst > all the agentic stuff :) > > On Fri, Jul 24, 2026 at 1:43 AM Aaron Parecki <aaron= > [email protected]> wrote: > >> Hi Judith, >> >> Thanks for your presentation today. In case it wasn't clear from my >> comment at the mic, I wrote up a draft to show how you can achieve what I >> believe is your goal using the existing OAuth protocol. There is one aspect >> that could be improved beyond core OAuth which is described in this draft. >> >> The example in this section is probably the quickest way to see what I >> mean: >> >> >> https://www.ietf.org/archive/id/draft-parecki-oauth-refresh-token-scope-response-00.html#section-6.1 >> >> I'm happy to add you as a co-author if you would like to pursue this. >> >> Aaron >> >> >> >> >> >> ---------- Forwarded message --------- >> From: <[email protected]> >> Date: Fri, Jul 24, 2026 at 10:37 AM >> Subject: New Version Notification for >> draft-parecki-oauth-refresh-token-scope-response-00.txt >> To: Aaron Parecki <[email protected]> >> >> >> A new version of Internet-Draft >> draft-parecki-oauth-refresh-token-scope-response-00.txt has been >> successfully >> submitted by Aaron Parecki and posted to the >> IETF repository. >> >> Name: draft-parecki-oauth-refresh-token-scope-response >> Revision: 00 >> Title: OAuth 2.0 Refresh Token Scope >> Date: 2026-07-24 >> Group: Individual Submission >> Pages: 12 >> URL: >> https://www.ietf.org/archive/id/draft-parecki-oauth-refresh-token-scope-response-00.txt >> Status: >> https://datatracker.ietf.org/doc/draft-parecki-oauth-refresh-token-scope-response/ >> HTML: >> https://www.ietf.org/archive/id/draft-parecki-oauth-refresh-token-scope-response-00.html >> HTMLized: >> https://datatracker.ietf.org/doc/html/draft-parecki-oauth-refresh-token-scope-response >> >> >> Abstract: >> >> This specification defines a new OAuth 2.0 token response parameter, >> refresh_token_scope, that indicates the scope authorized for a >> refresh token when it differs from the scope of the access token >> issued alongside it. This allows clients to discover that a refresh >> token carries broader authorization than the initial access token, >> enabling just-in-time requests for elevated access without requiring >> a new authorization flow. >> >> >> >> The IETF Secretariat >> >> >> _______________________________________________ >> OAuth mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> >
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
