OAuth WG Daily Report - 2026-04-28
- generated_at_utc:
2026-04-28T08:31:51Z - snapshot:
/home/runner/work/identity-deep-dive/identity-deep-dive/tracks/oauth-wg/data/snapshots/2026-04-28T083138Z
Top Priorities
| Rank | Draft | Score | Updated | Key State | Repo |
|---|---|---|---|---|---|
| 1 | draft-ietf-oauth-identity-chaining |
135 | 2026-04-27T16:03:43Z | Active, IANA - Review Needed | oauth-identity-chaining |
| 2 | draft-ietf-oauth-rfc7523bis |
118 | 2026-04-20T20:12:59Z | Active, Reviews assigned | draft-ietf-oauth-rfc7523bis |
| 3 | draft-ietf-oauth-transaction-tokens |
108 | 2026-03-27T12:21:42Z | Active, I-D Exists | oauth-transaction-tokens |
| 4 | draft-ietf-oauth-sd-jwt-vc |
105 | 2026-04-24T18:54:46Z | Active, I-D Exists | oauth-sd-jwt-vc |
| 5 | draft-ietf-oauth-status-list |
94 | 2026-04-20T11:14:05Z | Active, Expert Reviews OK | draft-ietf-oauth-status-list |
| 6 | draft-ietf-oauth-identity-assertion-authz-grant |
76 | 2026-04-22T22:16:37Z | Active, I-D Exists | oauth-identity-assertion-authz-grant |
| 7 | draft-ietf-oauth-cross-device-security |
65 | 2026-03-04T14:06:34Z | Active, No IANA Actions | oauth-cross-device-security |
| 8 | draft-ietf-oauth-browser-based-apps |
65 | 2025-12-04T18:51:39Z | Active, No IANA Actions | oauth-browser-based-apps |
| 9 | draft-ietf-oauth-attestation-based-client-auth |
58 | 2026-03-02T22:12:21Z | Active, I-D Exists | draft-ietf-oauth-attestation-based-client-auth |
| 10 | draft-ietf-oauth-rfc8725bis |
45 | 2026-03-22T09:15:20Z | Active, Publication Requested | draft-ietf-oauth-rfc8725bis |
Active Drafts
| Draft | Rev | Updated | States |
|---|---|---|---|
draft-ietf-oauth-identity-chaining |
10 | 2026-04-27T16:03:43Z | Active, IANA - Review Needed, In Last Call |
draft-ietf-oauth-sd-jwt-vc |
16 | 2026-04-24T18:54:46Z | Active, I-D Exists, WG Consensus: Waiting for Write-Up |
draft-ietf-oauth-identity-assertion-authz-grant |
03 | 2026-04-22T22:16:37Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-rfc7523bis |
10 | 2026-04-20T20:12:59Z | Active, Reviews assigned, Version Changed - Review Needed |
draft-ietf-oauth-status-list |
20 | 2026-04-20T11:14:05Z | Active, Expert Reviews OK, Version Changed - Review Needed |
draft-ietf-oauth-transaction-tokens |
08 | 2026-03-27T12:21:42Z | Active, I-D Exists, In WG Last Call |
draft-ietf-oauth-rfc8725bis |
04 | 2026-03-22T09:15:20Z | Active, Publication Requested, Submitted to IESG for Publication |
draft-ietf-oauth-cross-device-security |
16 | 2026-03-04T14:06:34Z | Active, No IANA Actions, Version Changed - Review Needed |
draft-ietf-oauth-attestation-based-client-auth |
08 | 2026-03-02T22:12:21Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-v2-1 |
15 | 2026-03-02T18:53:37Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-spiffe-client-auth |
01 | 2026-03-02T17:13:18Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-security-topics-update |
01 | 2026-03-02T13:29:59Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-client-id-metadata-document |
01 | 2026-03-02T03:28:49Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-first-party-apps |
03 | 2026-02-28T01:50:14Z | Active, I-D Exists, WG Document |
draft-ietf-oauth-refresh-token-expiration |
01 | 2026-02-27T22:51:29Z | Active, I-D Exists, WG Document |
Repo Watch
| Repo | Pushed | Open Issues |
|---|---|---|
oauth-wg/draft-ietf-oauth-attestation-based-client-auth |
2026-04-28T00:30:28Z | 21 |
oauth-wg/oauth-identity-assertion-authz-grant |
2026-04-28T00:16:08Z | 16 |
oauth-wg/draft-ietf-oauth-client-id-metadata-document |
2026-04-28T00:12:25Z | 38 |
oauth-wg/oauth-sd-jwt-vc |
2026-04-26T01:01:02Z | 1 |
oauth-wg/oauth-identity-chaining |
2026-04-24T22:35:44Z | 0 |
oauth-wg/oauth-transaction-tokens |
2026-04-23T00:37:08Z | 16 |
oauth-wg/draft-ietf-oauth-status-list |
2026-04-21T00:36:21Z | 0 |
oauth-wg/draft-ietf-oauth-rfc7523bis |
2026-04-20T20:12:52Z | 1 |
oauth-wg/oauth-v2-1 |
2026-04-16T00:29:30Z | 49 |
oauth-wg/oauth-first-party-apps |
2026-03-13T11:10:31Z | 8 |
oauth-wg/draft-ietf-oauth-rfc8725bis |
2026-03-03T00:12:27Z | 0 |
oauth-wg/oauth-cross-device-security |
2026-03-02T16:16:24Z | 0 |
Recent Pull Requests
oauth-wg/draft-ietf-oauth-attestation-based-client-auth#1893 trust (2026-04-26T19:55:17Z)oauth-wg/oauth-identity-assertion-authz-grant#91minor corrections to the example requests (2026-04-26T17:54:17Z)oauth-wg/oauth-identity-assertion-authz-grant#88Clarify step-up authentication semantics for token exchange (2026-04-25T17:22:16Z)oauth-wg/oauth-identity-chaining#185note Aaron's move in the doc history (2026-04-24T22:31:09Z)oauth-wg/oauth-identity-chaining#184Move Mr. Parecki from contributor to author (2026-04-24T22:09:17Z)oauth-wg/oauth-sd-jwt-vc#407Document History now with more 17 (2026-04-24T19:01:00Z)oauth-wg/oauth-sd-jwt-vc#405shepherd review edits (2026-04-24T18:45:08Z)oauth-wg/oauth-sd-jwt-vc#406shepherd review edits + Move Display & Claim Metadata to be subsections of SD-JWT VC Type Metadata (2026-04-24T18:33:46Z)oauth-wg/oauth-identity-chaining#183AD comments (2026-04-24T16:56:12Z)oauth-wg/oauth-identity-assertion-authz-grant#89add headings for IdP/RAS metadata (2026-04-23T17:33:23Z)
Recent Issues
oauth-wg/oauth-identity-assertion-authz-grant#92ID-JAG standard claim change suggestions (2026-04-27T17:31:48Z)oauth-wg/draft-ietf-oauth-client-id-metadata-document#30Client metadata retrieval can be abused to make server issued requests (2026-04-26T14:40:03Z)oauth-wg/oauth-identity-chaining#182AD Feedback (2026-04-24T16:13:39Z)oauth-wg/oauth-identity-chaining#139Updates to reflect changes to RFC7523 (jwt_privatekey attack) (2026-04-23T23:16:04Z)oauth-wg/oauth-identity-chaining#181Question: DPoP proof handling across trust domain boundaries (2026-04-23T23:12:57Z)oauth-wg/oauth-identity-assertion-authz-grant#90Addauthorization_grant_profiles_supportedto client metadata too (2026-04-22T22:34:36Z)oauth-wg/oauth-identity-assertion-authz-grant#80Adding Optionalactor_tokento ID-JAG for Explicit Actor Modeling (2026-04-22T22:11:33Z)oauth-wg/oauth-identity-assertion-authz-grant#76Clarity in preconditions for LLM Agent using Enterprise Tools section (2026-04-22T22:11:32Z)oauth-wg/oauth-identity-assertion-authz-grant#71Add recommendations/considerations for user provisioning (2026-04-22T22:11:32Z)oauth-wg/oauth-identity-assertion-authz-grant#75Potential Usecase: Whitelabeling of SaaS Services (2026-04-22T22:11:32Z)
Organization Events
2026-04-28T00:30:29ZPushEventoauth-wg/draft-ietf-oauth-attestation-based-client-auth2026-04-28T00:16:09ZPushEventoauth-wg/oauth-identity-assertion-authz-grant2026-04-28T00:12:26ZPushEventoauth-wg/draft-ietf-oauth-client-id-metadata-document2026-04-27T20:20:26ZWatchEventoauth-wg/oauth-v2-1started2026-04-27T17:31:49ZIssuesEventoauth-wg/oauth-identity-assertion-authz-grantID-JAG standard claim change suggestions2026-04-26T19:54:54ZPushEventoauth-wg/draft-ietf-oauth-attestation-based-client-auth2026-04-26T19:54:29ZPushEventoauth-wg/draft-ietf-oauth-attestation-based-client-auth2026-04-26T17:54:17ZPullRequestEventoauth-wg/oauth-identity-assertion-authz-grantopened2026-04-26T17:39:51ZForkEventoauth-wg/oauth-identity-assertion-authz-grantforked2026-04-26T01:01:03ZPushEventoauth-wg/oauth-sd-jwt-vc2026-04-26T00:11:42ZPushEventoauth-wg/oauth-identity-assertion-authz-grant2026-04-25T17:22:15ZIssueCommentEventoauth-wg/oauth-identity-assertion-authz-grantClarify step-up authentication semantics for token exchange2026-04-25T17:19:17ZIssueCommentEventoauth-wg/oauth-identity-assertion-authz-grantClarify step-up authentication semantics for token exchange2026-04-24T22:35:45ZPushEventoauth-wg/oauth-identity-chaining2026-04-24T22:35:24ZReleaseEventoauth-wg/oauth-identity-chainingpublished2026-04-24T22:31:34ZPushEventoauth-wg/oauth-identity-chaining2026-04-24T22:31:09ZDeleteEventoauth-wg/oauth-identity-chaining2026-04-24T22:31:08ZPullRequestEventoauth-wg/oauth-identity-chainingmerged2026-04-24T22:31:08ZPushEventoauth-wg/oauth-identity-chaining2026-04-24T22:16:28ZPushEventoauth-wg/oauth-identity-chaining
Mailarchive Signals
- weekly_digest_count:
2 - [OAUTH-WG] New Internet-Draft: Transaction Tokens for Agents - https://mailarchive.ietf.org/arch/msg/oauth/tauE5NNF3FHEswCOjUxVYT3SclI/
- [OAUTH-WG] Re: [saag] ZTNP / ZTIP – attestation-gated authorization & intent-bound delegation (seeking venue guidance) - https://mailarchive.ietf.org/arch/msg/oauth/4NsgxLGrY48sjWXO7DOQ_qRAQsU/
- [OAUTH-WG] [IANA #1449104] expert review for draft-ietf-oauth-rfc7523bis (OAuth Token Endpoint Authentication Methods) - https://mailarchive.ietf.org/arch/msg/oauth/zKuAdSYPImZBYcuJIrSbL1DOqeY/
- [OAUTH-WG] Re: Mohamed Boucadair's No Objection on draft-ietf-oauth-rfc7523bis-10: (with COMMENT) - https://mailarchive.ietf.org/arch/msg/oauth/nTFHH_-okfZVkmE13mlnhiIpRxI/
- [OAUTH-WG] Last Call: <draft-ietf-oauth-identity-chaining-10.txt> (OAuth Identity and Authorization Chaining Across Domains) to Proposed Standard - https://mailarchive.ietf.org/arch/msg/oauth/nLT9-L3nhy0qAK4AJTmdwrce9Jo/
- [OAUTH-WG] Mohamed Boucadair's No Objection on draft-ietf-oauth-rfc7523bis-10: (with COMMENT) - https://mailarchive.ietf.org/arch/msg/oauth/SjAn38U6bLhVKNxRLm2KKrZRQUM/
- [OAUTH-WG] spiffe_wit should be independent of attestation-based client - https://mailarchive.ietf.org/arch/msg/oauth/WzXnpBn2TXJ_SqOBiMbJM1GMeF4/
- [OAUTH-WG] Weekly github digest (OAuth Activity Summary) - https://mailarchive.ietf.org/arch/msg/oauth/zOsg2oC2f0BIUmVWOkE4hlDdGPU/
Next Actions
- Evaluate the top 3 items in
Top Prioritiesas weekly deep-dive candidates. - Separately track comment deadlines for
In Last Call/In WG Last Calldrafts. - For repos with a sudden spike in activity, create a scaffold in
deep-dives/to capture key discussion points.