{"id":2653,"date":"2025-04-23T14:27:03","date_gmt":"2025-04-23T21:27:03","guid":{"rendered":"https:\/\/self-issued.info\/?p=2653"},"modified":"2025-04-23T14:27:03","modified_gmt":"2025-04-23T21:27:03","slug":"oauth-2-0-protected-resource-metadata-is-now-rfc-9728","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2653","title":{"rendered":"OAuth 2.0 Protected Resource Metadata is now RFC 9728"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" alt=\"OAuth logo\" src=\"https:\/\/self-issued.info\/images\/oauth_logo_120x120.png\" \/>The OAuth 2.0 Protected Resource Metadata specification has been published as <a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc9728.html\">RFC 9728<\/a>!  This is certainly the longest that any RFC that I have worked on has taken from <a href=\"https:\/\/datatracker.ietf.org\/doc\/draft-jones-oauth-resource-metadata\/00\/\">initial individual draft<\/a> to RFC &#8211; August 2016 to April 2025 &#8211; 8 years and 8 months.  <a href=\"https:\/\/self-issued.info\/?p=2615\">As we discussed<\/a> at the <a href=\"https:\/\/oauth.secworkshop.events\/osw2025\">2025 OAuth Security Workshop<\/a> in Reykjav\u00edk:<\/p>\n<blockquote><p>\nTiming can be fickle.  What may not be useful at one time can turn out to be useful later.\n<\/p><\/blockquote>\n<p>Per the abstract, here&#8217;s what it adds to the OAuth 2.0 family of specifications:<\/p>\n<blockquote><p>\nThis specification defines a metadata format that an OAuth 2.0 client or authorization server can use to obtain the information needed to interact with an OAuth 2.0 protected resource.\n<\/p><\/blockquote>\n<p>It joins the OAuth 2.0 Dynamic Client Registration Protocol <a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc7591.html\">[RFC 7591<\/a>] and OAuth 2.0 Authorization Server Metadata [<a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc8414.html\">RFC 8414<\/a>] specifications, completing the set of metadata specifications for all three OAuth 2.0 roles.<\/p>\n<p>I&#8217;m glad to have co-authored this one with long-time collaborator <a href=\"https:\/\/www.linkedin.com\/in\/phunt\/\">Phil Hunt<\/a> and new collaborator <a href=\"https:\/\/www.linkedin.com\/in\/aaronparecki\/\">Aaron Parecki<\/a>.  And I&#8217;m proud of the fact that all of <a href=\"https:\/\/datatracker.ietf.org\/person\/michael_b_jones@hotmail.com#rfcs-1\">my last five RFCs<\/a> had a co-author for which it was their first RFC; in this case, it&#8217;s Aaron&#8217;s first RFC.<\/p>\n<p>Congratulations, Aaron!  It was a pleasure working on this with you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The OAuth 2.0 Protected Resource Metadata specification has been published as RFC 9728! This is certainly the longest that any RFC that I have worked on has taken from initial individual draft to RFC &#8211; August 2016 to April 2025 &#8211; 8 years and 8 months. As we discussed at the 2025 OAuth Security Workshop [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,26,25],"tags":[],"class_list":["post-2653","post","type-post","status-publish","format-standard","hentry","category-ietf","category-oauth","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2653"}],"version-history":[{"count":3,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2653\/revisions"}],"predecessor-version":[{"id":2656,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2653\/revisions\/2656"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}