This update to OAuth 2.1 captures the items we've discussed in the last few months, and includes some additional editorial clarifications as usual. Please refer to the changelog in the draft for full details.
Aaron On Wed, Sep 2, 2026 at 5:22 PM <[email protected]> wrote: > Internet-Draft draft-ietf-oauth-v2-1-16.txt is now available. It is a work > item of the Web Authorization Protocol (OAUTH) WG of the IETF. > > Title: The OAuth 2.1 Authorization Framework > Authors: Dick Hardt > Aaron Parecki > Torsten Lodderstedt > Name: draft-ietf-oauth-v2-1-16.txt > Pages: 103 > Dates: 2026-09-02 > > Abstract: > > The OAuth 2.1 authorization framework enables an application to > obtain limited access to a protected resource, either on behalf of a > resource owner by orchestrating an approval interaction between the > resource owner and an authorization service, or by allowing the > application to obtain access on its own behalf. This specification > replaces and obsoletes the OAuth 2.0 Authorization Framework > described in RFC 6749 and the Bearer Token Usage in RFC 6750. > > The IETF datatracker status page for this Internet-Draft is: > https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/ > > There is also an HTML version available at: > https://www.ietf.org/archive/id/draft-ietf-oauth-v2-1-16.html > > A diff from the previous version is available at: > https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-v2-1-16 > > Internet-Drafts are also available by rsync at: > rsync.ietf.org::internet-drafts > > > _______________________________________________ > OAuth mailing list -- [email protected] > To unsubscribe send an email to [email protected] >
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
