Identity & Access
OAuth 2.0
OAuth 2.0 Authorization Framework
Formal standard
Global
IETF
Since 2012
The delegated authorisation framework behind almost every modern API: a client obtains a scoped, time limited token instead of the user's credentials.
Scopes and token lifetimes are the enforcement points a control framework leans on, and token issuance logs are the evidence that least privilege was more than an intention.
At a glance
- Category
- Identity & Access
- Jurisdiction
- Global
- Governance
- IETF
- Status
- RFC 6749 with a large family of extensions
- First released
- 2012
Links
Related frameworks
Other entries under Identity & Access.
- XACML: eXtensible Access Control Markup Language
- SAML: Security Assertion Markup Language
- OpenID Connect: OpenID Connect Core
- SCIM: System for Cross-domain Identity Management
See OAuth 2.0 in context
Open the interactive Data Landscape for Regulation to compare OAuth 2.0 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.