| 10027 | Best Current Practice for Security of Cross-Device FlowsP. Kasselman, D. Fett, F. Skokan | Best Current Practice | August 2026 |
| 10017 | OAuth 2.0 for Browser-Based ApplicationsA. Parecki, P. De Ryck, D. Waite | Best Current Practice | August 2026 |
| 9901 | Selective Disclosure for JSON Web TokensD. Fett, K. Yasuda, B. Campbell | Proposed Standard | November 2025 |
| 9728 | OAuth 2.0 Protected Resource MetadataM.B. Jones, P. Hunt, A. Parecki | Proposed Standard | April 2025 |
| 9701 | JSON Web Token (JWT) Response for OAuth Token IntrospectionT. Lodderstedt, Ed., V. Dzhuvinov | Proposed Standard | January 2025 |
| 9700 | Best Current Practice for OAuth 2.0 SecurityT. Lodderstedt, J. Bradley, A. Labunets, D. Fett | Best Current Practice | January 2025 |
| 9470 | OAuth 2.0 Step Up Authentication Challenge ProtocolV. Bertocci, B. Campbell | Proposed Standard | September 2023 |
| 9449 | OAuth 2.0 Demonstrating Proof of Possession (DPoP)D. Fett, B. Campbell, J. Bradley, T. Lodderstedt, M. Jones, D. Waite | Proposed Standard | September 2023 |
| 9396 | OAuth 2.0 Rich Authorization RequestsT. Lodderstedt, J. Richer, B. Campbell | Proposed Standard | May 2023 |
| 9278 | JWK Thumbprint URIM. Jones, K. Yasuda | Proposed Standard | August 2022 |
| 9207 | OAuth 2.0 Authorization Server Issuer IdentificationK. Meyer zu Selhausen, D. Fett | Proposed Standard | March 2022 |
| 9126 | OAuth 2.0 Pushed Authorization RequestsT. Lodderstedt, B. Campbell, N. Sakimura, D. Tonge, F. Skokan | Proposed Standard | September 2021 |
| 9101 | The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR)N. Sakimura, J. Bradley, M. Jones | Proposed Standard | August 2021 |
| 9068 | JSON Web Token (JWT) Profile for OAuth 2.0 Access TokensV. Bertocci | Proposed Standard | October 2021 |
| 8725 | JSON Web Token Best Current PracticesY. Sheffer, D. Hardt, M. Jones | Best Current Practice | February 2020 |
| 8707 | Resource Indicators for OAuth 2.0B. Campbell, J. Bradley, H. Tschofenig | Proposed Standard | February 2020 |
| 8705 | OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access TokensB. Campbell, J. Bradley, N. Sakimura, T. Lodderstedt | Proposed Standard | February 2020 |
| 8693 | OAuth 2.0 Token ExchangeM. Jones, A. Nadalin, B. Campbell, Ed., J. Bradley, C. Mortimore | Proposed Standard | January 2020 |
| 8628 | OAuth 2.0 Device Authorization GrantW. Denniss, J. Bradley, M. Jones, H. Tschofenig | Proposed Standard | August 2019 |
| 8414 | OAuth 2.0 Authorization Server MetadataM. Jones, N. Sakimura, J. Bradley | Proposed Standard | June 2018 |
| 8252 | OAuth 2.0 for Native AppsW. Denniss, J. Bradley | Best Current Practice | October 2017 |
| 8176 | Authentication Method Reference ValuesM. Jones, P. Hunt, A. Nadalin | Proposed Standard | June 2017 |
| 7800 | Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)M. Jones, J. Bradley, H. Tschofenig | Proposed Standard | April 2016 |
| 7662 | OAuth 2.0 Token IntrospectionJ. Richer, Ed. | Proposed Standard | October 2015 |
| 7636 | Proof Key for Code Exchange by OAuth Public ClientsN. Sakimura, Ed., J. Bradley, N. Agarwal | Proposed Standard | September 2015 |
| 7592 | OAuth 2.0 Dynamic Client Registration Management ProtocolJ. Richer, Ed., M. Jones, J. Bradley, M. Machulak | Experimental | July 2015 |
| 7591 | OAuth 2.0 Dynamic Client Registration ProtocolJ. Richer, Ed., M. Jones, J. Bradley, M. Machulak, P. Hunt | Proposed Standard | July 2015 |
| 7523 | JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization GrantsM. Jones, B. Campbell, C. Mortimore | Proposed Standard | May 2015 |
| 7522 | Security Assertion Markup Language (SAML) 2.0 Profile for OAuth 2.0 Client Authentication and Authorization GrantsB. Campbell, C. Mortimore, M. Jones | Proposed Standard | May 2015 |
| 7521 | Assertion Framework for OAuth 2.0 Client Authentication and Authorization GrantsB. Campbell, C. Mortimore, M. Jones, Y. Goland | Proposed Standard | May 2015 |
| 7519 | JSON Web Token (JWT)M. Jones, J. Bradley, N. Sakimura | Proposed Standard | May 2015 |
| 7009 | OAuth 2.0 Token RevocationT. Lodderstedt, Ed., S. Dronia, M. Scurtescu | Proposed Standard | August 2013 |
| 6819 | OAuth 2.0 Threat Model and Security ConsiderationsT. Lodderstedt, Ed., M. McGloin, P. Hunt | Informational | January 2013 |
| 6755 | An IETF URN Sub-Namespace for OAuthB. Campbell, H. Tschofenig | Informational | October 2012 |
| 6750 | The OAuth 2.0 Authorization Framework: Bearer Token UsageM. Jones, D. Hardt | Proposed Standard | October 2012 |
| 6749 | The OAuth 2.0 Authorization FrameworkD. Hardt, Ed. | Proposed Standard | October 2012 |