RFC 9126: OAuth 2.0 Pushed Authorization Requests
In plain English — editorial summary, not part of the RFC
This document defines the pushed authorization request (PAR) endpoint, which allows clients to push the payload of an OAuth 2.0 authorization request to the authorization server via a direct request and provides them with a request URI that is used as reference to the data in a subsequent call to the authorization endpoint.
Document record
- Document ID
- RFC9126
- Published
- September 2021
- Authors
- T. Lodderstedt; B. Campbell; N. Sakimura; D. Tonge; F. Skokan
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 18
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9207OAuth 2.0 Authorization Server Issuer IdentificationCurrent
March 2022
- RFC 9396OAuth 2.0 Rich Authorization RequestsCurrent
May 2023
- RFC 9449OAuth 2.0 Demonstrating Proof of Possession (DPoP)Current
September 2023
- RFC 9470OAuth 2.0 Step Up Authentication Challenge ProtocolCurrent
September 2023
- RFC 9901Selective Disclosure for JSON Web TokensCurrent
November 2025
- RFC 10027Best Current Practice for Security of Cross-Device FlowsCurrent
August 2026
- RFC 9132Distributed Denial-of-Service Open Threat Signaling (DOTS) Signal Channel SpecificationCurrent
September 2021
- RFC 9133Controlling Filtering Rules Using Distributed Denial-of-Service Open Threat Signaling (DOTS) Signal ChannelCurrent
September 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?