Markdown Version | Transcript | Session Recording | Session Materials

Session Date/Time: 16 Mar 2026 06:00

OAUTH

IETF 125 - OAuth Working Group Minutes

Summary

The OAUTH Working Group met at IETF 125 to progress core specifications and address emerging use cases. Key highlights included finalizing the technical direction for OAuth 2.1 and OAuth 2.0 for First-Party Applications, alongside significant discussions on AI Agent authorization, SPIFFE client authentication, and Rich Authorization Request (RAR) metadata. The group reached a consensus to deprecate the "plain" PKCE challenge method in OAuth 2.1 and decided against extending PAR for the First-Party Apps specification.


Key Discussion Points

1. Chairs Update

Presenters: Hannes Tschofenig and Mike Jones Slides: Chairs Update

2. OAuth 2.1

Presenter: Aaron Parecki Draft: draft-ietf-oauth-v2-1 Slides: OAuth 2.1

3. OAuth Client ID Metadata Document

Presenter: Aaron Parecki Draft: draft-ietf-oauth-client-id-metadata-document Slides: Client ID Metadata Document

4. OAuth 2.0 for First-Party Applications

Presenter: Aaron Parecki Draft: draft-ietf-oauth-first-party-apps Slides: OAuth for First Party Apps

5. Identity Assertion JWT Authorization Grant

Presenter: Aaron Parecki Draft: draft-ietf-oauth-identity-assertion-authz-grant Slides: Identity Assertion Authorization Grant

6. Updates to OAuth 2.0 Security Best Current Practice

Presenter: Kaishuai Luo Draft: draft-ietf-oauth-security-topics-update Slides: Updates to OAuth 2.0 Security Best Current Practice

7. RAR Metadata and Error Signaling

Presenter: Yaron Sheffer Slides: RAR Metadata and Error Signaling

8. OAuth 2.0 for Native Clients with Federation

Presenter: Yaron Sheffer Slides: OAuth 2.0 for native clients with federation

9. Additional Hash Algorithms for OAuth 2.0

Presenter: Aaron Parecki (for Filip Skokan) Slides: Additional Hash Algorithms for OAuth 2.0

10. SPIFFE Client Authentication

Presenter: Arnt Richard Johansen Draft: draft-ietf-oauth-spiffe-client-auth Slides: OAuth SPIFFE Client Authentication

11. AI Agents and Transaction Tokens


Decisions and Action Items

  1. OAuth 2.1: Deprecate the plain PKCE code challenge method.
  2. First-Party Apps: Proceed to WGLC without PAR integration.
  3. Action Item: Aaron Parecki to perform an editorial pass on draft-ietf-oauth-identity-assertion-authz-grant prior to WGLC.
  4. Action Item: Chairs to coordinate review cycles for the new AI-related drafts and the Security Topics update.

Next Steps

Related Documents

draft-ietf-oauth-attestation-based-client-auth, draft-ietf-oauth-client-id-metadata-document, draft-ietf-oauth-first-party-apps, draft-ietf-oauth-identity-assertion-authz-grant, draft-ietf-oauth-security-topics-update, draft-ietf-oauth-spiffe-client-auth, draft-ietf-oauth-transaction-tokens, draft-ietf-oauth-v2-1