Markdown Version | Recording 1 | Recording 2

Session Date/Time: 18 Mar 2025 06:00

oauth

Summary

The OAuth working group meeting covered several key topics, including the Token Status List, Attestation-Based Client Authentication, OAuth 2.1, OAuth for First-Party Apps, Client ID Scheme, and updates to the Security BCP. The discussion focused on recent changes, outstanding issues, and potential future directions for each topic.

Key Discussion Points

Decisions and Action Items

Next Steps


Session Date/Time: 21 Mar 2025 02:30

oauth

Summary

This OAuth working group meeting covered several important topics, including updates on SD-JWT and SD-JWT-VC, a vulnerability in the JWT assertion profile (RFC 7523), transaction tokens, identity chaining, and proposals for improvements to token endpoint responses. The discussion around the RFC 7523 vulnerability and its potential fixes sparked debate about the best approach.

Key Discussion Points

Decisions and Action Items

Next Steps