RFC 8705 · PROPOSED STANDARD · 2020

OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens

Overview

RFC 8705, “OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens”, is a Proposed Standard document published in February 2020 by B. Campbell, J. Bradley, N. Sakimura, T. Lodderstedt. The canonical text is published by the RFC Editor.

Abstract

This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are provided a mechanism for binding access tokens to a client's mutual-TLS certificate, and OAuth protected resources are provided a method for ensuring that such an access token presented to it was issued to the client presenting the token.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 8705 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2020

Who Is Online

In total there are 107 users online: 0 registered, 97 guests and 10 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Majestic Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372