RFC 9449 · PROPOSED STANDARD · 2023

OAuth 2.0 Demonstrating Proof of Possession

Overview

RFC 9449, “OAuth 2.0 Demonstrating Proof of Possession”, is a Proposed Standard document published in September 2023 by D. Fett, B. Campbell, J. Bradley, T. Lodderstedt, M. Jones, D. Waite. The canonical text is published by the RFC Editor.

Abstract

This document describes a mechanism for sender-constraining OAuth 2.0 tokens via a proof-of-possession mechanism on the application level. This mechanism allows for the detection of replay attacks with access and refresh tokens.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9449 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2023

Who Is Online

In total there are 55 users online: 0 registered, 45 guests and 10 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Facebook Googlebot Majestic Other Bot SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 356