How to use this reference
Compare an owned integration's documented design against the standard and record deviations and compensating controls.
Before reading
- OAuth roles and authorization flows
- HTTP redirects and TLS
- Basic token and session concepts
Context and limits
Sources and provenance
- RFC 9700: Best Current Practice for OAuth 2.0 Security Internet Engineering Task Force / RFC Editor · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.