RFC 6819: OAuth 2.0 Threat Model and Security Considerations
In plain English — editorial summary, not part of the RFC
This document gives additional security considerations for OAuth, beyond those in the OAuth 2.0 specification, based on a comprehensive threat model for the OAuth 2.0 protocol. This document is not an Internet Standards Track specification; it is published for informational purposes.
Document record
- Document ID
- RFC6819
- Published
- January 2013
- Authors
- T. Lodderstedt; M. McGloin; P. Hunt
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 71
- Also known as
- —
- Updated by:
- RFC 9700
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8120Mutual Authentication Protocol for HTTPCurrent
April 2017
- RFC 8121Mutual Authentication Protocol for HTTP: Cryptographic Algorithms Based on the Key Agreement Mechanism 3 (KAM3)Current
April 2017
- RFC 2660The Secure HyperText Transfer ProtocolCurrent
August 1999
- RFC 6686Resolution of the Sender Policy Framework (SPF) and Sender ID ExperimentsCurrent
July 2012
- RFC 7155Diameter Network Access Server ApplicationCurrent
April 2014
- RFC 7236Initial Hypertext Transfer Protocol (HTTP) Authentication Scheme RegistrationsCurrent
June 2014
- RFC 7423Diameter Applications Design GuidelinesCurrent
November 2014
- RFC 7615HTTP Authentication-Info and Proxy-Authentication-Info Response Header FieldsObsoleted
September 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?