RFC 9207 · PROPOSED STANDARD · 2022

OAuth 2.0 Authorization Server Issuer Identification

Overview

RFC 9207, “OAuth 2.0 Authorization Server Issuer Identification”, is a Proposed Standard document published in March 2022 by K. Meyer zu Selhausen, D. Fett. The canonical text is published by the RFC Editor.

Abstract

This document specifies a new parameter called iss. This parameter is used to explicitly include the issuer identifier of the authorization server in the authorization response of an OAuth authorization flow. The iss parameter serves as an effective countermeasure to "mix-up attacks".

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9207 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2022

Who Is Online

In total there are 58 users online: 0 registered, 54 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Facebook Other Bot Other Crawler SemrushBot

Users active in the past 15 minutes. Total registered members: 354