Skip to main content

10. Security Considerations

10. Security Considerations

In addition to all the security considerations discussed in OAuth 2.0 [RFC6819], the security considerations in [RFC7515], [RFC7516], [RFC7518], and [RFC8725] need to be considered. Also, there are several academic papers such as [BASIN] that provide useful insight into the security properties of protocols like OAuth.

In consideration of the above, this document advises taking the following security considerations into account.

See 10.1. Choice of Algorithms through 10.8. Cross-JWT Confusion.