RFC 9207: OAuth 2.0 Authorization Server Issuer Identification
In plain English — editorial summary, not part of the RFC
This document specifies a new parameter called iss. This parameter is used to explicitly include the issuer identifier of the authorization server in the authorization response of an OAuth authorization flow. The iss parameter serves as an effective countermeasure to "mix-up attacks".
Document record
- Document ID
- RFC9207
- Published
- March 2022
- Authors
- K. Meyer zu Selhausen; D. Fett
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 9
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9126OAuth 2.0 Pushed Authorization RequestsCurrent
September 2021
- RFC 9396OAuth 2.0 Rich Authorization RequestsCurrent
May 2023
- RFC 9449OAuth 2.0 Demonstrating Proof of Possession (DPoP)Current
September 2023
- RFC 9470OAuth 2.0 Step Up Authentication Challenge ProtocolCurrent
September 2023
- RFC 9901Selective Disclosure for JSON Web TokensCurrent
November 2025
- RFC 10027Best Current Practice for Security of Cross-Device FlowsCurrent
August 2026
- RFC 9216S/MIME Example Keys and CertificatesCurrent
April 2022
- RFC 9133Controlling Filtering Rules Using Distributed Denial-of-Service Open Threat Signaling (DOTS) Signal ChannelCurrent
September 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?