{
  "number": 7628,
  "title": "A Set of Simple Authentication and Security Layer (SASL) Mechanisms for OAuth",
  "authors": [
    "W. Mills",
    "T. Showalter",
    "H. Tschofenig"
  ],
  "published": "2015-08",
  "status": "Proposed Standard",
  "stream": "IETF",
  "area": "sec",
  "working_group": "kitten",
  "pages": 21,
  "formats": [
    "TXT",
    "HTML"
  ],
  "abstract": "OAuth enables a third-party application to obtain limited access to a protected resource, either on behalf of a resource owner by orchestrating an approval interaction or by allowing the third-party application to obtain access on its own behalf.\n\nThis document defines how an application client uses credentials obtained via OAuth over the Simple Authentication and Security Layer (SASL) to access a protected resource at a resource server. Thereby, it enables schemes defined within the OAuth framework for non-HTTP-based application protocols.\n\nClients typically store the user's long-term credential. This does, however, lead to significant security vulnerabilities, for example, when such a credential leaks. A significant benefit of OAuth for usage in those clients is that the password is replaced by a shared secret with higher entropy, i.e., the token. Tokens typically provide limited access rights and can be managed and revoked separately from the user's long-term password.",
  "draft": "draft-ietf-kitten-sasl-oauth-23",
  "doi": "10.17487/RFC7628",
  "errata_url": "https://www.rfc-editor.org/errata/rfc7628",
  "urls": {
    "html": "https://rfc.dk/rfc7628/",
    "text": "https://rfc.dk/rfc7628.txt",
    "rfc_editor": "https://www.rfc-editor.org/rfc/rfc7628",
    "datatracker": "https://datatracker.ietf.org/doc/rfc7628/"
  },
  "text_modified": "2015-09-01T04:54:00Z"
}
