RFC 9700: Best Current Practice for OAuth 2.0 Security
In plain English — editorial summary, not part of the RFC
This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.
Document record
- Document ID
- RFC9700
- Published
- January 2025
- Authors
- T. Lodderstedt; J. Bradley; A. Labunets; D. Fett
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- sec
- Pages
- 46
- Also known as
- BCP240
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8725JSON Web Token Best Current PracticesCurrent
February 2020
- RFC 6946Processing of IPv6 "Atomic" FragmentsCurrent
May 2013
- RFC 4272BGP Security Vulnerabilities AnalysisCurrent
January 2006
- RFC 9701JSON Web Token (JWT) Response for OAuth Token IntrospectionCurrent
January 2025
- RFC 9708Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax (CMS)Current
January 2025
- RFC 9709Encryption Key Derivation in the Cryptographic Message Syntax (CMS) Using HKDF with SHA-256Current
January 2025
- RFC 9690Use of the RSA-KEM Algorithm in the Cryptographic Message Syntax (CMS)Current
February 2025
- RFC 9711The Entity Attestation Token (EAT)Current
April 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?