Identity & Access

OAuth 2.0

OAuth 2.0 Authorization Framework

Formal standard Global IETF Since 2012

The delegated authorisation framework behind almost every modern API: a client obtains a scoped, time limited token instead of the user's credentials.

Scopes and token lifetimes are the enforcement points a control framework leans on, and token issuance logs are the evidence that least privilege was more than an intention.

At a glance

Category
Identity & Access
Jurisdiction
Global
Governance
IETF
Status
RFC 6749 with a large family of extensions
First released
2012

Links

Related frameworks

Other entries under Identity & Access.

See OAuth 2.0 in context

Open the interactive Data Landscape for Regulation to compare OAuth 2.0 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.