RFC 9700: Running OAuth 2.0 securely
Summary
RFC 9700 brings together current security practices for OAuth 2.0 and rejects risky historical patterns. A flexible authorisation framework needs secure profiles and defaults. Best practices can later explicitly replace early standard options.
Ideas
- Authorization code with PKCE protects public clients.
- Exact redirect URI checks prevent redirection attacks.
- Sender-constrained tokens reduce reuse after theft.
Remarks
- RFC 9700 has the status “Best Current Practice”; current errata and successor documents should also be checked.
Recommendations
- Use the authorization code flow with PKCE.
- Disable outdated flows and check redirect URIs exactly.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.