Available Flows
Specs & references
Authoritative reading list for OAuth 2.0 โ core specs, security considerations, and companion standards.
Core specs
ยท The specifications that define this protocol.Security & privacy
ยท Dedicated security and privacy considerations.Companion specs
ยท Extensions, hardenings, and supporting RFCs.- RFC 7636 โ Proof Key for Code Exchange (PKCE)
- RFC 7662 โ Token Introspection
- RFC 7009 โ Token Revocation
- RFC 8414 โ Authorization Server Metadata
- RFC 8693 โ Token Exchange
- RFC 8707 โ Resource Indicators
- RFC 9207 โ Authorization Server Issuer Identification
AS Mix-Up defence.
- RFC 9449 โ DPoP (Demonstrating Proof of Possession)
- RFC 9101 โ JWT-Secured Authorization Request (JAR)
- RFC 9126 โ Pushed Authorization Requests (PAR)
OAuth 2.0 Features
Authorization Code Flow
Standard flow for server-side applications
PKCE for Public Clients
Enhanced security for SPAs and mobile apps (RFC 7636)
Client Credentials
Machine-to-machine authentication