OAuth WG Daily Report - 2026-08-03
- generated_at_utc:
2026-08-03T09:53:41+00:00 - snapshot_date:
2026-08-03
Top Priorities
| Rank | Draft | Score | Updated | Key State | Repo |
|---|---|---|---|---|---|
| 1 | draft-ietf-oauth-transaction-tokens |
125 | 2026-07-30T17:51:33Z | Active, I-D Exists | oauth-transaction-tokens |
| 2 | draft-ietf-oauth-rfc8725bis |
108 | 2026-07-22T08:25:27Z | Active, Version Changed - Review Needed | draft-ietf-oauth-rfc8725bis |
| 3 | draft-ietf-oauth-sd-jwt-vc |
91 | 2026-07-15T13:11:02Z | Active, AD Evaluation | oauth-sd-jwt-vc |
| 4 | draft-ietf-oauth-cross-device-security |
90 | 2026-07-31T04:47:59Z | Active, No IANA Actions | oauth-cross-device-security |
| 5 | draft-ietf-oauth-rfc7523bis |
73 | 2026-07-23T20:02:17Z | Active, RFC-Ed-Ack | draft-ietf-oauth-rfc7523bis |
| 6 | draft-ietf-oauth-identity-chaining |
73 | 2026-07-22T07:07:08Z | Active, RFC-Ed-Ack | oauth-identity-chaining |
| 7 | draft-ietf-oauth-browser-based-apps |
73 | 2026-07-17T22:27:30Z | Active, No IANA Actions | oauth-browser-based-apps |
| 8 | draft-ietf-oauth-status-list |
65 | 2026-06-30T16:55:53Z | Active, RFC-Ed-Ack | draft-ietf-oauth-status-list |
| 9 | draft-ietf-oauth-identity-assertion-authz-grant |
65 | 2026-05-21T22:18:28Z | Active, I-D Exists | oauth-identity-assertion-authz-grant |
| 10 | draft-ietf-oauth-client-id-metadata-document |
63 | 2026-07-06T19:55:37Z | Active, I-D Exists | draft-ietf-oauth-client-id-metadata-document |
Active Drafts
| Draft | Rev | Updated | States |
|---|---|---|---|
draft-ietf-oauth-cross-device-security |
16 | 2026-07-31T04:47:59Z | Active, No IANA Actions, Version Changed - Review Needed |
draft-ietf-oauth-transaction-tokens |
11 | 2026-07-30T17:51:33Z | Active, I-D Exists, In WG Last Call |
draft-ietf-oauth-rfc7523bis |
11 | 2026-07-23T20:02:17Z | Active, RFC-Ed-Ack, Expert Reviews OK |
draft-ietf-oauth-rfc8725bis |
07 | 2026-07-22T08:25:27Z | Active, Version Changed - Review Needed, IESG Evaluation |
draft-ietf-oauth-identity-chaining |
17 | 2026-07-22T07:07:08Z | Active, RFC-Ed-Ack, Expert Reviews OK |
draft-ietf-oauth-browser-based-apps |
27 | 2026-07-17T22:27:30Z | Active, No IANA Actions, Version Changed - Review Needed |
draft-ietf-oauth-first-party-apps |
04 | 2026-07-15T17:25:20Z | Active, I-D Exists, WG Consensus: Waiting for Write-Up |
draft-ietf-oauth-sd-jwt-vc |
17 | 2026-07-15T13:11:02Z | Active, AD Evaluation, Submitted to IESG for Publication |
draft-ietf-oauth-attestation-based-client-auth |
10 | 2026-07-10T13:29:37Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-client-id-metadata-document |
02 | 2026-07-06T19:55:37Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-refresh-token-expiration |
03 | 2026-07-06T17:53:06Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-security-topics-update |
03 | 2026-07-06T06:41:36Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-status-list |
21 | 2026-06-30T16:55:53Z | Active, RFC-Ed-Ack, Expert Reviews OK |
draft-ietf-oauth-spiffe-client-auth |
02 | 2026-06-15T08:11:11Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-identity-assertion-authz-grant |
04 | 2026-05-21T22:18:28Z | Active, I-D Exists, WG Document |
Repo Watch
| Repo | Pushed | Open Issues |
|---|---|---|
oauth-wg/draft-ietf-oauth-attestation-based-client-auth |
2026-08-03T08:06:27Z | 4 |
oauth-wg/oauth-sd-jwt-vc |
2026-08-03T06:41:57Z | 2 |
oauth-wg/oauth-transaction-tokens |
2026-08-02T00:36:20Z | 1 |
oauth-wg/oauth-v2-1 |
2026-08-02T00:32:08Z | 48 |
oauth-wg/oauth-identity-assertion-authz-grant |
2026-08-02T00:19:40Z | 34 |
oauth-wg/draft-ietf-oauth-client-id-metadata-document |
2026-08-02T00:16:56Z | 44 |
oauth-wg/draft-ietf-oauth-rfc8725bis |
2026-08-01T17:57:35Z | 1 |
oauth-wg/oauth-spiffe-client-authentication |
2026-07-26T00:27:59Z | 12 |
oauth-wg/oauth-identity-chaining |
2026-07-19T14:00:40Z | 0 |
oauth-wg/oauth-browser-based-apps |
2026-07-06T20:04:24Z | 0 |
oauth-wg/rt-expiration |
2026-07-06T17:32:51Z | 4 |
oauth-wg/oauth-first-party-apps |
2026-07-01T20:41:17Z | 6 |
Recent Pull Requests
oauth-wg/draft-ietf-oauth-attestation-based-client-auth#215add clarifications for combined mode (2026-08-03T09:36:53Z)oauth-wg/draft-ietf-oauth-attestation-based-client-auth#220fix all IANA entries (hopefully) (2026-08-03T09:34:57Z)oauth-wg/draft-ietf-oauth-attestation-based-client-auth#219add considerations for profiling this draft (2026-08-03T08:22:22Z)oauth-wg/oauth-sd-jwt-vc#420feat: add optional inherits claim based on implementer's feedback (2026-08-03T06:41:16Z)oauth-wg/draft-ietf-oauth-rfc8725bis#57Recommend fully-specified JOSE algorithms (RFC 9864) (2026-08-01T17:57:03Z)oauth-wg/draft-ietf-oauth-rfc8725bis#56IESG: address Ketan Talaulikar ballot COMMENT (2026-08-01T17:33:56Z)oauth-wg/draft-ietf-oauth-rfc8725bis#55Update Appendix A: changes from RFC 8725 (2026-08-01T17:32:11Z)oauth-wg/oauth-identity-assertion-authz-grant#118Add mTLS certificate binding for ID-JAG sender constraining (2026-08-01T04:11:55Z)oauth-wg/draft-ietf-oauth-attestation-based-client-auth#217mention that RFC7521 is not used (2026-07-31T17:23:19Z)oauth-wg/draft-ietf-oauth-rfc8725bis#53SECDIR: clarify Nested JWT validation in Section 3.3 (2026-07-31T12:16:09Z)
Recent Issues
oauth-wg/draft-ietf-oauth-attestation-based-client-auth#212Allow for alternative key-bound JWT formats (2026-08-03T08:05:00Z)oauth-wg/draft-ietf-oauth-attestation-based-client-auth#211Key-bound refresh tokens are limited to the key lifetime (2026-08-03T08:04:59Z)oauth-wg/draft-ietf-oauth-attestation-based-client-auth#210Client ID == assertion subject restriction (2026-08-03T08:04:59Z)oauth-wg/oauth-identity-assertion-authz-grant#83Interoperability gap: JIT provisioning and identity claim negotiation (2026-08-02T19:58:35Z)oauth-wg/draft-ietf-oauth-rfc8725bis#54IESG ballot COMMENT: Ketan Talaulikar (No Objection) (2026-08-02T09:36:53Z)oauth-wg/draft-ietf-oauth-rfc8725bis#50Update Appendix A: changes from RFC 8725 (2026-08-01T17:32:12Z)oauth-wg/oauth-v2-1#253How should an Authorization properly implement section 4.1.2.1. Error Response Error Messages (2026-08-01T16:19:22Z)oauth-wg/draft-ietf-oauth-client-id-metadata-document#92Provide guidance on omission oftoken_endpoint_auth_methodfield (2026-08-01T01:53:05Z)oauth-wg/oauth-identity-assertion-authz-grant#117Sender constraining the ID-JAG via mTLS-cert binding (2026-08-01T01:41:36Z)oauth-wg/draft-ietf-oauth-attestation-based-client-auth#200Draft 9 - Relationship with rfc7521 (2026-07-31T17:23:20Z)
Organization Events
2026-08-03T09:36:54ZPullRequestReviewEventoauth-wg/draft-ietf-oauth-attestation-based-client-authcreated2026-08-03T09:34:57ZPullRequestReviewEventoauth-wg/draft-ietf-oauth-attestation-based-client-authcreated2026-08-03T09:34:31ZPullRequestReviewCommentEventoauth-wg/draft-ietf-oauth-attestation-based-client-authcreated2026-08-03T09:33:53ZPullRequestReviewCommentEventoauth-wg/draft-ietf-oauth-attestation-based-client-authcreated2026-08-03T09:33:36ZPullRequestReviewCommentEventoauth-wg/draft-ietf-oauth-attestation-based-client-authcreated2026-08-03T08:22:22ZIssueCommentEventoauth-wg/draft-ietf-oauth-attestation-based-client-authadd considerations for profiling this draft2026-08-03T08:17:44ZPullRequestReviewCommentEventoauth-wg/draft-ietf-oauth-attestation-based-client-authcreated2026-08-03T08:06:27ZPushEventoauth-wg/draft-ietf-oauth-attestation-based-client-auth2026-08-03T08:04:59ZPushEventoauth-wg/draft-ietf-oauth-attestation-based-client-auth2026-08-03T08:04:58ZPullRequestEventoauth-wg/draft-ietf-oauth-attestation-based-client-authmerged2026-08-03T08:05:00ZIssuesEventoauth-wg/draft-ietf-oauth-attestation-based-client-authAllow for alternative key-bound JWT formats2026-08-03T08:05:00ZIssuesEventoauth-wg/draft-ietf-oauth-attestation-based-client-authKey-bound refresh tokens are limited to the key lifetime2026-08-03T08:04:59ZIssuesEventoauth-wg/draft-ietf-oauth-attestation-based-client-authClient ID == assertion subject restriction2026-08-03T06:41:57ZPushEventoauth-wg/oauth-sd-jwt-vc2026-08-03T06:41:16ZPushEventoauth-wg/oauth-sd-jwt-vc2026-08-03T05:14:25ZPullRequestReviewEventoauth-wg/oauth-sd-jwt-vccreated2026-08-02T21:40:59ZPullRequestReviewEventoauth-wg/oauth-sd-jwt-vccreated2026-08-02T20:06:50ZPullRequestEventoauth-wg/oauth-sd-jwt-vcopened2026-08-02T20:06:39ZPushEventoauth-wg/oauth-sd-jwt-vc2026-08-02T20:02:14ZCreateEventoauth-wg/oauth-sd-jwt-vc
Mailarchive Signals
- weekly_digest_count:
2 - [OAUTH-WG] Weekly github digest (OAuth Activity Summary) - https://mailarchive.ietf.org/arch/msg/oauth/qrM5kDuMakE1wulcMMcp7pVFfSQ/
- [OAUTH-WG] Re: Request for Review: Delegated Refresh Tokens for OAuth 2.0 Token Exchange (-04) - https://mailarchive.ietf.org/arch/msg/oauth/lnUxHmRqOGrXNKx5qUmwXLZoOyk/
- [OAUTH-WG] Re: Question on ID-JAG topology: Public Agent + API Gateway / MCP Proxy scenario - https://mailarchive.ietf.org/arch/msg/oauth/fwfVf74iHcE3PoQKO6alpwvCuSc/
- [OAUTH-WG] Re: Ketan Talaulikar's No Objection on draft-ietf-oauth-rfc8725bis-07: (with COMMENT) - https://mailarchive.ietf.org/arch/msg/oauth/FAxZ_B9YemUu9J2VazB7cu2005w/
- [OAUTH-WG] Re: Request for Review: Delegated Refresh Tokens for OAuth 2.0 Token Exchange (-04) - https://mailarchive.ietf.org/arch/msg/oauth/ncO4akG56REW25TqKlj7AdxW_Zc/
- [OAUTH-WG] Ketan Talaulikar's No Objection on draft-ietf-oauth-rfc8725bis-07: (with COMMENT) - https://mailarchive.ietf.org/arch/msg/oauth/h_MPR_KJcqinJ2hAXyEkBsXUi4w/
- [OAUTH-WG] Re: Request for Review: Delegated Refresh Tokens for OAuth 2.0 Token Exchange (-04) - https://mailarchive.ietf.org/arch/msg/oauth/JhCiABapidum2xr7tk3sJv0pVtQ/
- [OAUTH-WG] Re: draft-ietf-oauth-rfc8725bis-07 ietf last call Secdir review - https://mailarchive.ietf.org/arch/msg/oauth/dA-MMqZgctSaVq4ohPALBBF0m2k/
Next Actions
- Evaluate the top 3 items in
Top Prioritiesas weekly deep-dive candidates. - Separately track comment deadlines for
In Last Call/In WG Last Calldrafts. - For repos with a sudden spike in activity, create a scaffold in
deep-dives/to capture key discussion points.