I-D Action: draft-li-oauth-delegated-authorization-03.txt

[email protected] Fri, 24 Jul 2026 03:05:29 -0700
Newsgroups gmane.ietf.announce
Message-ID <178488752947.826074.10386085789877797501@dt-datatracker-d4d6ff9d9-ql5mb>
Internet-Draft draft-li-oauth-delegated-authorization-03.txt is now available.

   Title:   OAuth 2.0 Delegated Authorization
   Authors: Ruochen Li
            Haiguang Wang
            Chunchi Peter Liu
            Tieyan Li
   Name:    draft-li-oauth-delegated-authorization-03.txt
   Pages:   62
   Dates:   2026-07-24

Abstract:

   This specification defines Delegated Authorization Tokens, key-bound
   tokens that enable an OAuth client to delegate a constrained subset
   of its authorization to another client without contacting the
   authorization server for each delegation.  An authorization server
   issues the root token and binds it to a client key.  That client can
   use the bound key either to prove possession when accessing a
   protected resource or to sign a further token bound to a delegate
   client's key.  Resource servers validate the ordered token chain, the
   restrictions imposed at every delegation step, and a DPoP proof
   signed by the key bound to the leaf token.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-li-oauth-delegated-authorization/

There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-li-oauth-delegated-authorization-03

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-li-oauth-delegated-authorization-03

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]