RFC 6749
The OAuth 2.0 Authorization Framework, October 2012
- Canonical URL:
- https://www.rfc-editor.org/rfc/rfc6749.txt
- File formats:


- Status:
- PROPOSED STANDARD
- Obsoletes:
- RFC 5849
- Updated by:
- RFC 8252
- Author:
- D. Hardt, Ed.
- Stream:
- IETF
- Source:
- oauth (sec)
DOI: 10.17487/RFC6749
Discuss this RFC: Send questions or comments to [email protected]
Other actions: View Errata | Submit Errata | Find IPR Disclosures from the IETF
Abstract
The OAuth 2.0 authorization framework enables a third-party application to obtain limited access to an HTTP service, either on behalf of a resource owner by orchestrating an approval interaction between the resource owner and the HTTP service, or by allowing the third-party application to obtain access on its own behalf. This specification replaces and obsoletes the OAuth 1.0 protocol described in RFC 5849. [STANDARDS-TRACK]
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 4844.