Markdown Version | Recording 1 | Recording 2

Session Date/Time: 03 Nov 2025 19:30

OAUTH Session Minutes

Summary

The OAUTH session covered a broad range of topics, including updates on current working group drafts, detailed presentations on SD-JWT VC, Identity Assertion and Authorization Grant (ID-JAG), and targeted fixes for OAuth 2.0 JWT Client Authorization Authentication and Authorization Based Authorization Grants. Discussions also included updates on OAuth 2.1, potential browser swapping attacks, an extension proposal for DPoP for non-HTTP transports (DPoP Proof), and a new framework for OAuth delegated authorization. Key decisions were made to move forward with working group last calls for SD-JWT VC and the JWT Client Auth document, and to refine guidance for OAuth 2.1 and browser-swapping attack mitigations.

Key Discussion Points

Working Group Draft Status Update

SD-JWT VC (Selective Disclosure for JWTs)

Identity Assertion and Authorization Grant (ID-JAG)

OAuth 2.0 JWT Client Authorization Authentication and Authorization Based Authorization Grants

OAuth 2.1 Updates

Browser Swapping Attacks in OAuth 2.0

DPoP Proof (Media Quick)

OAuth Delegated Authorization

Decisions and Action Items

Next Steps


Session Date/Time: 07 Nov 2025 19:30

OAUTH Session - IETF 124

Summary

The OAUTH session at IETF 124 covered a packed agenda of drafts, ranging from updates on client attestation and client ID metadata to new proposals for DPoP usage, browserless app-to-app federation, and refresh token/authorization expiration. Significant discussion revolved around the evolving definition and usage of client IDs, the balance between increased security and complexity, and the appropriate scope for new OAuth extensions. Several drafts saw calls for adoption or indicated readiness for Working Group Last Call, with others continuing to solicit feedback.

Key Discussion Points

Aditation-based Client Authentication (Paul Winstanley for Hannes Tschofenig)

Client ID Metadata Document (Aaron Parecki)

Deepop for Device Authorization Grant (Aaron Parecki)

Deepop for JWT Authorization Grant (Aaron Parecki)

Browserless App-to-App (Aram K. Kocharyan)

Refresh Token and Authorization Expiration (Nick Watson)

Separating Deepop Bindings for Access and Refresh Tokens (Yaroslav Tkachenko, Lauren Warth)

Spiffy Client Authentication (Christian Schuster)

Transaction Tokens (Christian Schuster)

JWT BCP Updates (Mike Jones)

Decisions and Action Items

Next Steps