RFC 9470: OAuth 2.0 Step Up Authentication Challenge Protocol
In plain English — editorial summary, not part of the RFC
It is not uncommon for resource servers to require different authentication strengths or recentness according to the characteristics of a request. This document introduces a mechanism that resource servers can use to signal to a client that the authentication event associated with the access token of the current request does not meet its authentication requirements and, further, how to meet them. This document also codifies a mechanism for a client to request that an authorization server achieve a specific authentication strength or recentness when processing an authorization request.
Document record
- Document ID
- RFC9470
- Published
- September 2023
- Authors
- V. Bertocci; B. Campbell
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 14
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9449OAuth 2.0 Demonstrating Proof of Possession (DPoP)Current
September 2023
- RFC 9396OAuth 2.0 Rich Authorization RequestsCurrent
May 2023
- RFC 9207OAuth 2.0 Authorization Server Issuer IdentificationCurrent
March 2022
- RFC 9126OAuth 2.0 Pushed Authorization RequestsCurrent
September 2021
- RFC 9901Selective Disclosure for JSON Web TokensCurrent
November 2025
- RFC 10027Best Current Practice for Security of Cross-Device FlowsCurrent
August 2026
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
- RFC 9464Internet Key Exchange Protocol Version 2 (IKEv2) Configuration for Encrypted DNSCurrent
November 2023
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?