UpdatedPROPOSED STANDARDIETF stream

RFC 6750: The OAuth 2.0 Authorization Framework: Bearer Token Usage

Still current, but amended. Parts of this document are changed or extended by RFC 8996, RFC 9700. Read both.

In plain English — editorial summary, not part of the RFC

This specification describes how to use bearer tokens in HTTP requests to access OAuth 2.0 protected resources. Any party in possession of a bearer token (a "bearer") can use it to get access to the associated resources (without demonstrating possession of a cryptographic key). To prevent misuse, bearer tokens need to be protected from disclosure in storage and in transport. [STANDARDS-TRACK]

Document record

Document ID
RFC6750
Published
October 2012
Authors
M. Jones; D. Hardt
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
18
Also known as
Updated by:
RFC 8996, RFC 9700

Topics

Referenced by

2 later RFCs formally update or obsolete part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/6750-the-oauth-2-0-authorization-framework-bearer-token-usage