RFC 9200: Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework (ACE-OAuth)
In plain English — editorial summary, not part of the RFC
This specification defines a framework for authentication and authorization in Internet of Things (IoT) environments called ACE-OAuth. The framework is based on a set of building blocks including OAuth 2.0 and the Constrained Application Protocol (CoAP), thus transforming a well-known and widely used authorization solution into a form suitable for IoT devices. Existing specifications are used where possible, but extensions are added and profiles are defined to better serve the IoT use cases.
Document record
- Document ID
- RFC9200
- Published
- August 2022
- Authors
- L. Seitz; G. Selander; E. Wahlstroem; S. Erdtman; H. Tschofenig
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 72
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9201Additional OAuth Parameters for Authentication and Authorization for Constrained Environments (ACE)Current
August 2022
- RFC 9203The Object Security for Constrained RESTful Environments (OSCORE) Profile of the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
August 2022
- RFC 9237An Authorization Information Format (AIF) for Authentication and Authorization for Constrained Environments (ACE)Current
August 2022
- RFC 9770Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
June 2025
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
- RFC 9820Authentication Service Based on the Extensible Authentication Protocol (EAP) for Use with the Constrained Application Protocol (CoAP)Current
September 2025
- RFC 8323CoAP (Constrained Application Protocol) over TCP, TLS, and WebSocketsUpdated
February 2018
- RFC 7959Block-Wise Transfers in the Constrained Application Protocol (CoAP)Updated
August 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?