{"draft":"draft-ietf-oauth-iss-auth-resp-05","doc_id":"RFC9207","title":"OAuth 2.0 Authorization Server Issuer Identification","authors":["K. Meyer zu Selhausen","D. Fett"],"format":["HTML","TEXT","PDF","XML"],"page_count":"9","pub_status":"PROPOSED STANDARD","status":"PROPOSED STANDARD","source":"Web Authorization Protocol","abstract":"This document specifies a new parameter called iss. This parameter is\r\nused to explicitly include the issuer identifier of the authorization\r\nserver in the authorization response of an OAuth authorization flow.\r\nThe iss parameter serves as an effective countermeasure to \"mix-up\r\nattacks\".","pub_date":"March 2022","keywords":["security","oauth2"],"obsoletes":[],"obsoleted_by":[],"updates":[],"updated_by":[],"see_also":[],"doi":"10.17487\/RFC9207","errata_url":null}