ietf-corpus

rfc-6750

The OAuth 2.0 Authorization Framework: Bearer Token Usage

M. Jones, D. Hardt
date2012-10 streamIETF areasec wgoauth statusPROPOSED STANDARD pages18 canonicalhttps://www.rfc-editor.org/rfc/rfc6750 doi10.17487/RFC6750 errataview
This specification describes how to use bearer tokens in HTTP requests to access OAuth 2.0 protected resources. Any party in possession of a bearer token (a "bearer") can use it to get access to the associated resources (without demonstrating possession of a cryptographic key). To prevent misuse, bearer tokens need to be protected from disclosure in storage and in transport. [STANDARDS-TRACK]

updated by