JSON Web Token Profile for OAuth 2.0 Client Authentication and Authorization Grants
RFC 7523, “JSON Web Token Profile for OAuth 2.0 Client Authentication and Authorization Grants”, is a Proposed Standard document published in May 2015 by M. Jones, B. Campbell, C. Mortimore. The canonical text is published by the RFC Editor.
Abstract
This specification defines the use of a JSON Web Token (JWT) Bearer Token as a means for requesting an OAuth 2.0 access token as well as for client authentication.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7523 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7522 Security Assertion Markup Language 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants
- RFC 7524 Inter-Area Point-to-Multipoint Segmented Label Switched Paths
- RFC 7521 Assertion Framework for OAuth 2.0 Client Authentication and Authorization Grants
- RFC 7525 Recommendations for Secure Use of Transport Layer Security and Datagram Transport Layer Security
- RFC 7520 Examples of Protecting Content Using JSON Object Signing and Encryption
- RFC 7526 Deprecating the Anycast Prefix for 6to4 Relay Routers
- RFC 7519 JSON Web Token
- RFC 7527 Enhanced Duplicate Address Detection