bk99.de entertain the web since 1997

RFC 9700: Running OAuth 2.0 securely

Summary

RFC 9700 brings together current security practices for OAuth 2.0 and rejects risky historical patterns. A flexible authorisation framework needs secure profiles and defaults. Best practices can later explicitly replace early standard options.

Ideas

  • Authorization code with PKCE protects public clients.
  • Exact redirect URI checks prevent redirection attacks.
  • Sender-constrained tokens reduce reuse after theft.

Remarks

  • RFC 9700 has the status “Best Current Practice”; current errata and successor documents should also be checked.

Recommendations

  • Use the authorization code flow with PKCE.
  • Disable outdated flows and check redirect URIs exactly.

References

Read the RFC at the RFC Editor

Search the Web Archive