CurrentBEST CURRENT PRACTICEIETF streamBCP240

RFC 9700: Best Current Practice for OAuth 2.0 Security

In plain English — editorial summary, not part of the RFC

This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.

Document record

Document ID
RFC9700
Published
January 2025
Authors
T. Lodderstedt; J. Bradley; A. Labunets; D. Fett
Status
BEST CURRENT PRACTICE
Stream
IETF
Area
sec
Pages
46
Also known as
BCP240

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9700-best-current-practice-for-oauth-2-0-security