RFC 9200 · PROPOSED STANDARD · 2022

Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework

Overview

RFC 9200, “Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework”, is a Proposed Standard document published in August 2022 by L. Seitz, G. Selander, E. Wahlstroem, S. Erdtman, H. Tschofenig. The canonical text is published by the RFC Editor.

Abstract

This specification defines a framework for authentication and authorization in Internet of Things (IoT) environments called ACE-OAuth. The framework is based on a set of building blocks including OAuth 2.0 and the Constrained Application Protocol (CoAP), thus transforming a well-known and widely used authorization solution into a form suitable for IoT devices. Existing specifications are used where possible, but extensions are added and profiles are defined to better serve the IoT use cases.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9200 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2022

Who Is Online

In total there are 63 users online: 0 registered, 54 guests and 9 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372