Additional OAuth Parameters for Authentication and Authorization for Constrained Environments
RFC 9201, “Additional OAuth Parameters for Authentication and Authorization for Constrained Environments”, is a Proposed Standard document published in August 2022 by L. Seitz. The canonical text is published by the RFC Editor.
Abstract
This specification defines new parameters and encodings for the OAuth 2.0 token and introspection endpoints when used with the framework for Authentication and Authorization for Constrained Environments (ACE). These are used to express the proof-of-possession (PoP) key the client wishes to use, the PoP key that the authorization server has selected, and the PoP key the resource server uses to authenticate to the client.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9201 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9200 Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework
- RFC 9202 Datagram Transport Layer Security Profile for Authentication and Authorization for Constrained Environments
- RFC 9199 Considerations for Large Authoritative DNS Server Operators
- RFC 9203 The Object Security for Constrained RESTful Environments Profile of the Authentication and Authorization for Constrained Environments Framework
- RFC 9198 Advanced Unidirectional Route Assessment
- RFC 9204 QPACK: Field Compression for HTTP/3
- RFC 9197 Data Fields for In Situ Operations, Administration, and Maintenance
- RFC 9205 Building Protocols with HTTP