OAuth WG

OAuth Working Group drafts and implementations

Daily Report2026-08-03

OAuth WG Daily Report - 2026-08-03

  • generated_at_utc: 2026-08-03T09:53:41+00:00
  • snapshot_date: 2026-08-03

Top Priorities

Rank Draft Score Updated Key State Repo
1 draft-ietf-oauth-transaction-tokens 125 2026-07-30T17:51:33Z Active, I-D Exists oauth-transaction-tokens
2 draft-ietf-oauth-rfc8725bis 108 2026-07-22T08:25:27Z Active, Version Changed - Review Needed draft-ietf-oauth-rfc8725bis
3 draft-ietf-oauth-sd-jwt-vc 91 2026-07-15T13:11:02Z Active, AD Evaluation oauth-sd-jwt-vc
4 draft-ietf-oauth-cross-device-security 90 2026-07-31T04:47:59Z Active, No IANA Actions oauth-cross-device-security
5 draft-ietf-oauth-rfc7523bis 73 2026-07-23T20:02:17Z Active, RFC-Ed-Ack draft-ietf-oauth-rfc7523bis
6 draft-ietf-oauth-identity-chaining 73 2026-07-22T07:07:08Z Active, RFC-Ed-Ack oauth-identity-chaining
7 draft-ietf-oauth-browser-based-apps 73 2026-07-17T22:27:30Z Active, No IANA Actions oauth-browser-based-apps
8 draft-ietf-oauth-status-list 65 2026-06-30T16:55:53Z Active, RFC-Ed-Ack draft-ietf-oauth-status-list
9 draft-ietf-oauth-identity-assertion-authz-grant 65 2026-05-21T22:18:28Z Active, I-D Exists oauth-identity-assertion-authz-grant
10 draft-ietf-oauth-client-id-metadata-document 63 2026-07-06T19:55:37Z Active, I-D Exists draft-ietf-oauth-client-id-metadata-document

Active Drafts

Draft Rev Updated States
draft-ietf-oauth-cross-device-security 16 2026-07-31T04:47:59Z Active, No IANA Actions, Version Changed - Review Needed
draft-ietf-oauth-transaction-tokens 11 2026-07-30T17:51:33Z Active, I-D Exists, In WG Last Call
draft-ietf-oauth-rfc7523bis 11 2026-07-23T20:02:17Z Active, RFC-Ed-Ack, Expert Reviews OK
draft-ietf-oauth-rfc8725bis 07 2026-07-22T08:25:27Z Active, Version Changed - Review Needed, IESG Evaluation
draft-ietf-oauth-identity-chaining 17 2026-07-22T07:07:08Z Active, RFC-Ed-Ack, Expert Reviews OK
draft-ietf-oauth-browser-based-apps 27 2026-07-17T22:27:30Z Active, No IANA Actions, Version Changed - Review Needed
draft-ietf-oauth-first-party-apps 04 2026-07-15T17:25:20Z Active, I-D Exists, WG Consensus: Waiting for Write-Up
draft-ietf-oauth-sd-jwt-vc 17 2026-07-15T13:11:02Z Active, AD Evaluation, Submitted to IESG for Publication
draft-ietf-oauth-attestation-based-client-auth 10 2026-07-10T13:29:37Z Active, I-D Exists, WG Document
draft-ietf-oauth-client-id-metadata-document 02 2026-07-06T19:55:37Z Active, I-D Exists, WG Document
draft-ietf-oauth-refresh-token-expiration 03 2026-07-06T17:53:06Z Active, I-D Exists, WG Document
draft-ietf-oauth-security-topics-update 03 2026-07-06T06:41:36Z Active, I-D Exists, WG Document
draft-ietf-oauth-status-list 21 2026-06-30T16:55:53Z Active, RFC-Ed-Ack, Expert Reviews OK
draft-ietf-oauth-spiffe-client-auth 02 2026-06-15T08:11:11Z Active, I-D Exists, WG Document
draft-ietf-oauth-identity-assertion-authz-grant 04 2026-05-21T22:18:28Z Active, I-D Exists, WG Document

Repo Watch

Repo Pushed Open Issues
oauth-wg/draft-ietf-oauth-attestation-based-client-auth 2026-08-03T08:06:27Z 4
oauth-wg/oauth-sd-jwt-vc 2026-08-03T06:41:57Z 2
oauth-wg/oauth-transaction-tokens 2026-08-02T00:36:20Z 1
oauth-wg/oauth-v2-1 2026-08-02T00:32:08Z 48
oauth-wg/oauth-identity-assertion-authz-grant 2026-08-02T00:19:40Z 34
oauth-wg/draft-ietf-oauth-client-id-metadata-document 2026-08-02T00:16:56Z 44
oauth-wg/draft-ietf-oauth-rfc8725bis 2026-08-01T17:57:35Z 1
oauth-wg/oauth-spiffe-client-authentication 2026-07-26T00:27:59Z 12
oauth-wg/oauth-identity-chaining 2026-07-19T14:00:40Z 0
oauth-wg/oauth-browser-based-apps 2026-07-06T20:04:24Z 0
oauth-wg/rt-expiration 2026-07-06T17:32:51Z 4
oauth-wg/oauth-first-party-apps 2026-07-01T20:41:17Z 6

Recent Pull Requests

  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#215 add clarifications for combined mode (2026-08-03T09:36:53Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#220 fix all IANA entries (hopefully) (2026-08-03T09:34:57Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#219 add considerations for profiling this draft (2026-08-03T08:22:22Z)
  • oauth-wg/oauth-sd-jwt-vc#420 feat: add optional inherits claim based on implementer's feedback (2026-08-03T06:41:16Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#57 Recommend fully-specified JOSE algorithms (RFC 9864) (2026-08-01T17:57:03Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#56 IESG: address Ketan Talaulikar ballot COMMENT (2026-08-01T17:33:56Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#55 Update Appendix A: changes from RFC 8725 (2026-08-01T17:32:11Z)
  • oauth-wg/oauth-identity-assertion-authz-grant#118 Add mTLS certificate binding for ID-JAG sender constraining (2026-08-01T04:11:55Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#217 mention that RFC7521 is not used (2026-07-31T17:23:19Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#53 SECDIR: clarify Nested JWT validation in Section 3.3 (2026-07-31T12:16:09Z)

Recent Issues

  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#212 Allow for alternative key-bound JWT formats (2026-08-03T08:05:00Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#211 Key-bound refresh tokens are limited to the key lifetime (2026-08-03T08:04:59Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#210 Client ID == assertion subject restriction (2026-08-03T08:04:59Z)
  • oauth-wg/oauth-identity-assertion-authz-grant#83 Interoperability gap: JIT provisioning and identity claim negotiation (2026-08-02T19:58:35Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#54 IESG ballot COMMENT: Ketan Talaulikar (No Objection) (2026-08-02T09:36:53Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#50 Update Appendix A: changes from RFC 8725 (2026-08-01T17:32:12Z)
  • oauth-wg/oauth-v2-1#253 How should an Authorization properly implement section 4.1.2.1. Error Response Error Messages (2026-08-01T16:19:22Z)
  • oauth-wg/draft-ietf-oauth-client-id-metadata-document#92 Provide guidance on omission of token_endpoint_auth_method field (2026-08-01T01:53:05Z)
  • oauth-wg/oauth-identity-assertion-authz-grant#117 Sender constraining the ID-JAG via mTLS-cert binding (2026-08-01T01:41:36Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#200 Draft 9 - Relationship with rfc7521 (2026-07-31T17:23:20Z)

Organization Events

  • 2026-08-03T09:36:54Z PullRequestReviewEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth created
  • 2026-08-03T09:34:57Z PullRequestReviewEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth created
  • 2026-08-03T09:34:31Z PullRequestReviewCommentEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth created
  • 2026-08-03T09:33:53Z PullRequestReviewCommentEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth created
  • 2026-08-03T09:33:36Z PullRequestReviewCommentEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth created
  • 2026-08-03T08:22:22Z IssueCommentEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth add considerations for profiling this draft
  • 2026-08-03T08:17:44Z PullRequestReviewCommentEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth created
  • 2026-08-03T08:06:27Z PushEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth
  • 2026-08-03T08:04:59Z PushEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth
  • 2026-08-03T08:04:58Z PullRequestEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth merged
  • 2026-08-03T08:05:00Z IssuesEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth Allow for alternative key-bound JWT formats
  • 2026-08-03T08:05:00Z IssuesEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth Key-bound refresh tokens are limited to the key lifetime
  • 2026-08-03T08:04:59Z IssuesEvent oauth-wg/draft-ietf-oauth-attestation-based-client-auth Client ID == assertion subject restriction
  • 2026-08-03T06:41:57Z PushEvent oauth-wg/oauth-sd-jwt-vc
  • 2026-08-03T06:41:16Z PushEvent oauth-wg/oauth-sd-jwt-vc
  • 2026-08-03T05:14:25Z PullRequestReviewEvent oauth-wg/oauth-sd-jwt-vc created
  • 2026-08-02T21:40:59Z PullRequestReviewEvent oauth-wg/oauth-sd-jwt-vc created
  • 2026-08-02T20:06:50Z PullRequestEvent oauth-wg/oauth-sd-jwt-vc opened
  • 2026-08-02T20:06:39Z PushEvent oauth-wg/oauth-sd-jwt-vc
  • 2026-08-02T20:02:14Z CreateEvent oauth-wg/oauth-sd-jwt-vc

Mailarchive Signals

Next Actions

  1. Evaluate the top 3 items in Top Priorities as weekly deep-dive candidates.
  2. Separately track comment deadlines for In Last Call / In WG Last Call drafts.
  3. For repos with a sudden spike in activity, create a scaffold in deep-dives/ to capture key discussion points.

Weekly Digest2026-W32

OAuth WG Weekly Digest - 2026-W32

Window: 2026-07-27 to 2026-08-03 Generated at: 2026-08-03T11:09:46+00:00

Summary

  • Drafts updated this week: 2
  • PRs touched this week: 17
  • Issues touched this week: 17

Drafts Updated This Week

Draft Rev Updated States
draft-ietf-oauth-cross-device-security 16 2026-07-31T04:47:59Z Active, No IANA Actions, Version Changed - Review Needed
draft-ietf-oauth-transaction-tokens 11 2026-07-30T17:51:33Z Active, I-D Exists, In WG Last Call

Top Deep-Dive Candidates

Rank Draft Score Reasons
1 draft-ietf-oauth-transaction-tokens 125 lifecycle: In WG Last Call (+70); updated within 3 days (+25); repo activity: 15 (+30)
2 draft-ietf-oauth-rfc8725bis 108 lifecycle: IESG Evaluation (+70); updated within 30 days (+8); repo activity: 56 (+30)
3 draft-ietf-oauth-sd-jwt-vc 91 lifecycle: AD Evaluation (+55); updated within 30 days (+8); repo activity: 14 (+28)
4 draft-ietf-oauth-cross-device-security 90 lifecycle: RFC Ed Queue (+65); updated within 3 days (+25)
5 draft-ietf-oauth-rfc7523bis 73 lifecycle: RFC Ed Queue (+65); updated within 30 days (+8)
6 draft-ietf-oauth-identity-chaining 73 lifecycle: RFC Ed Queue (+65); updated within 30 days (+8)
7 draft-ietf-oauth-browser-based-apps 73 lifecycle: RFC Ed Queue (+65); updated within 30 days (+8)
8 draft-ietf-oauth-status-list 65 lifecycle: RFC Ed Queue (+65)
9 draft-ietf-oauth-identity-assertion-authz-grant 65 lifecycle: WG Document (+20); repo activity: 51 (+30); open issues: 34 (+15)
10 draft-ietf-oauth-client-id-metadata-document 63 lifecycle: WG Document (+20); updated within 30 days (+8); repo activity: 10 (+20)

Active PRs This Week

  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#215 add clarifications for combined mode (2026-08-03T10:32:53Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#220 fix all IANA entries (hopefully) (2026-08-03T09:34:57Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#219 add considerations for profiling this draft (2026-08-03T08:22:22Z)
  • oauth-wg/oauth-sd-jwt-vc#420 feat: add optional inherits claim based on implementer's feedback (2026-08-03T06:41:16Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#57 Recommend fully-specified JOSE algorithms (RFC 9864) (2026-08-01T17:57:03Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#56 IESG: address Ketan Talaulikar ballot COMMENT (2026-08-01T17:33:56Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#55 Update Appendix A: changes from RFC 8725 (2026-08-01T17:32:11Z)
  • oauth-wg/oauth-identity-assertion-authz-grant#118 Add mTLS certificate binding for ID-JAG sender constraining (2026-08-01T04:11:55Z)
  • oauth-wg/draft-ietf-oauth-attestation-based-client-auth#217 mention that RFC7521 is not used (2026-07-31T17:23:19Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#53 SECDIR: clarify Nested JWT validation in Section 3.3 (2026-07-31T12:16:09Z)
  • oauth-wg/oauth-sd-jwt-vc#419 idnits stuff (2026-07-31T08:00:54Z)
  • oauth-wg/oauth-transaction-tokens#368 fixed doc history typo (2026-07-30T17:11:39Z)
  • oauth-wg/oauth-transaction-tokens#367 Update draft with editorial text and changes from 07 to 08 (2026-07-29T19:00:56Z)
  • oauth-wg/oauth-transaction-tokens#366 Refine description of Txn-Token JWT body claims (2026-07-29T18:55:19Z)
  • oauth-wg/draft-ietf-oauth-rfc8725bis#51 SHOULD NOT to MUST NOT on JWT libraries using none without explicit instruction from caller (2026-07-28T22:30:00Z)