RFC 9700 · BEST CURRENT PRACTICE · 2025

Best Current Practice for OAuth 2.0 Security

Overview

RFC 9700, “Best Current Practice for OAuth 2.0 Security”, is a Best Current Practice document published in January 2025 by T. Lodderstedt, J. Bradley, A. Labunets, D. Fett. It updates RFC 6749, RFC 6750, RFC 6819. The canonical text is published by the RFC Editor.

Abstract

This document describes best current security practice for OAuth 2.0. It updates and extends the threat model and security advice given in RFCs 6749, 6750, and 6819 to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0. Further, it deprecates some modes of operation that are deemed less secure or even insecure.

Abstract as published in the RFC, via rfc-editor.org.

What “Best Current Practice” means

Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.

Read this RFC

The canonical text of RFC 9700 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 6749 RFC 6750 RFC 6819
Other RFCs from 2025

Who Is Online

In total there are 125 users online: 0 registered, 118 guests and 7 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Facebook Googlebot Other Bot SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354