CurrentPROPOSED STANDARDIETF stream

RFC 9470: OAuth 2.0 Step Up Authentication Challenge Protocol

In plain English — editorial summary, not part of the RFC

It is not uncommon for resource servers to require different authentication strengths or recentness according to the characteristics of a request. This document introduces a mechanism that resource servers can use to signal to a client that the authentication event associated with the access token of the current request does not meet its authentication requirements and, further, how to meet them. This document also codifies a mechanism for a client to request that an authorization server achieve a specific authentication strength or recentness when processing an authorization request.

Document record

Document ID
RFC9470
Published
September 2023
Authors
V. Bertocci; B. Campbell
Status
PROPOSED STANDARD
Stream
IETF
Area
sec
Pages
14
Also known as

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9470-oauth-2-0-step-up-authentication-challenge-protocol