RFC 7628: A Set of Simple Authentication and Security Layer (SASL) Mechanisms for OAuth
In plain English — editorial summary, not part of the RFC
OAuth enables a third-party application to obtain limited access to a protected resource, either on behalf of a resource owner by orchestrating an approval interaction or by allowing the third-party application to obtain access on its own behalf. This document defines how an application client uses credentials obtained via OAuth over the Simple Authentication and Security Layer (SASL) to access a protected resource at a resource server. Thereby, it enables schemes defined within the OAuth framework for non-HTTP-based application protocols. Clients typically store the user's long-term credential. This does, however, lead to significant security vulnerabilities, for example, when such a credential leaks. A significant benefit of OAuth for usage in those clients is that the password is replaced by a shared secret with higher entropy, i.e., the token. Tokens typically provide limited access rights and can be managed and revoked separately from the user's long-term password.
Document record
- Document ID
- RFC7628
- Published
- August 2015
- Authors
- W. Mills; T. Showalter; H. Tschofenig
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 21
- Also known as
- —
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7627Transport Layer Security (TLS) Session Hash and Extended Master Secret ExtensionObsoleted
September 2015
- RFC 7632Endpoint Security Posture Assessment: Enterprise Use CasesCurrent
September 2015
- RFC 7634ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol (IKE) and IPsecCurrent
August 2015
- RFC 7636Proof Key for Code Exchange by OAuth Public ClientsCurrent
September 2015
- RFC 7619The NULL Authentication Method in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
August 2015
- RFC 7638JSON Web Key (JWK) ThumbprintCurrent
September 2015
- RFC 7617The 'Basic' HTTP Authentication SchemeCurrent
September 2015
- RFC 7616HTTP Digest Access AuthenticationCurrent
September 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?