RFC 9770 · PROPOSED STANDARD · 2025

Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments Framework

Overview

RFC 9770, “Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments Framework”, is a Proposed Standard document published in June 2025 by M. Tiloca, F. Palombini, S. Echeverria, G. Lewis. The canonical text is published by the RFC Editor.

Abstract

This document specifies a method of the Authentication and Authorization for Constrained Environments (ACE) framework, which allows an authorization server to notify clients and resource servers (i.e., registered devices) about revoked access tokens. As specified in this document, the method allows clients and resource servers (RSs) to access a Token Revocation List (TRL) on the authorization server by using the Constrained Application Protocol (CoAP), with the possible additional use of resource observation. Resulting (unsolicited) notifications of revoked access tokens complement alternative approaches such as token introspection, while not requiring additional endpoints on clients and RSs.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9770 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2025

Who Is Online

In total there are 98 users online: 0 registered, 92 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Googlebot Other Bot SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354