IETF drafts OAuth 2.1 Authorization Framework, set to obsolete OAuth 2.0 (RFC 6749)

jedisct1 · x · 2026-09-03

The IETF has published a new Internet-Draft of the OAuth 2.1 Authorization Framework (draft-ietf-oauth-v2-1-16, September 2026). OAuth 2.1 replaces and obsoletes the OAuth 2.0 framework in RFC 6749 and the Bearer Token usage in RFC 6750, letting applications obtain limited access to protected resources via an authorization service. Authors include D. Hardt (Hellō), A. Parecki (Okta), and T. Lodderstedt (SPRIND); discussion runs on the OAuth Working Group list, with source and issues on GitHub.

Original post →

More from Infra

Infra channel →