RFC 8705: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens
In plain English — editorial summary, not part of the RFC
This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are provided a mechanism for binding access tokens to a client's mutual-TLS certificate, and OAuth protected resources are provided a method for ensuring that such an access token presented to it was issued to the client presenting the token.
Document record
- Document ID
- RFC8705
- Published
- February 2020
- Authors
- B. Campbell; J. Bradley; N. Sakimura; T. Lodderstedt
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 24
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7800Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)Current
April 2016
- RFC 8693OAuth 2.0 Token ExchangeCurrent
January 2020
- RFC 8414OAuth 2.0 Authorization Server MetadataCurrent
June 2018
- RFC 8392CBOR Web Token (CWT)Current
May 2018
- RFC 9101The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR)Current
August 2021
- RFC 9728OAuth 2.0 Protected Resource MetadataCurrent
April 2025
- RFC 8725JSON Web Token Best Current PracticesCurrent
February 2020
- RFC 8747Proof-of-Possession Key Semantics for CBOR Web Tokens (CWTs)Current
March 2020
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?