Markdown Version | Session Recording

Session Date/Time: 06 Jan 2025 17:00

OAUTH

Summary

The OAUTH Working Group held an interim meeting to discuss the "OAUTH Client ID Scheme" draft (draft-aaron-oauth-client-id-scheme). The discussion centered on standardizing a mechanism for clients to publish metadata and use a URL as their client_id, particularly in scenarios where client pre-registration is not feasible. A significant portion of the discussion revolved around the ambiguity arising from existing deployments that already use HTTPS URLs as client_id in various contexts (e.g., OpenID Federation, client metadata documents), and how to introduce a clear scheme without breaking backward compatibility or introducing new security vulnerabilities. No formal decisions were made, but an action item was assigned to the author to refine the draft with explicit consideration of the proposed solutions.

Key Discussion Points

Decisions and Action Items

Next Steps