Markdown Version | Transcript | Recording 1 | Recording 2 | Session Materials

Session Date/Time: 23 Jul 2026 12:00 ✎ Suggest a correction

OAUTH

Summary

The OAUTH Working Group met to discuss the status of active working group documents, review security best practices, evaluate client metadata and SPIFFE-based client authentication, and explore agent authorization use cases and gaps. Key milestones include the transition of browser-based application guidance to the RFC Editor queue and growing implementation interest in cross-domain identity assertion. The session concluded with a panel on AI agent authentication, focusing on human-in-the-loop (HITL) patterns, non-deterministic API interactions, and credential governance, with plans to schedule an interim meeting to continue the agent authorization work.


Key Discussion Points

Chairs Update


Identity Assertion JWT Authorization Grant


Client ID Metadata Document


Updates to OAuth 2.0 Security Best Current Practice


OAuth SPIFFE Client Authentication


OAuth Transaction Authorization Challenge


Agentic Use Cases and Gaps Panel


Decisions and Action Items


Next Steps


Session Date/Time: 24 Jul 2026 07:00

OAUTH

Summary

The OAUTH Working Group met during IETF 126 on Friday. The session covered updates on active working group documents, presentations on multiple individual drafts (covering HTTP Message Signatures, Rich Authorization Request (RAR) Metadata, out-of-band client challenges, deferred token responses, envelope proof-of-possession, and SD-JWT delegation), an analysis of authorization policy languages in OAuth/AI environments, and a proposal to organize the working group's high volume of drafts using a clustering framework.


Key Discussion Points

Chairs Update


Attestation-Based Client Authentication


HTTP Message Signatures for OAuth PoP


RAR Metadata and Error Remediation


OAuth Client Challenge Protocol (Out-of-Band Approval)


Deferred Token Response (DTR)


Envelope Proof of Position (EPoP)


SD-JWT Delegation


Policy Language in OAuth (AI and Agentic Authorization)


Clustering of OAuth Work


Decisions and Action Items


Next Steps

Related Documents

draft-ietf-oauth-attestation-based-client-auth, draft-ietf-oauth-client-id-metadata-document, draft-ietf-oauth-first-party-apps, draft-ietf-oauth-identity-assertion-authz-grant, draft-ietf-oauth-security-topics-update, draft-ietf-oauth-spiffe-client-auth, draft-ietf-oauth-transaction-tokens, draft-ietf-oauth-v2-1, draft-mcguinness-oauth-token-exchange-cnf, draft-parecki-oauth-jwt-dpop-grant