Pushed Authorization Requests

GPTKB entity

Statements (29)
Predicate Object
gptkbp:instanceOf OAuth 2.0 extension
gptkbp:abbreviation gptkb:PAR
gptkbp:author gptkb:Daniel_Fett
gptkb:John_Bradley
gptkb:Nat_Sakimura
gptkb:Brian_Campbell
gptkb:Vittorio_Bertocci
gptkb:Joseph_Heenan
gptkbp:benefit prevents manipulation of authorization parameters
protects sensitive data in requests
gptkbp:category gptkb:International_Standard
gptkbp:definedIn gptkb:RFC_9126
gptkbp:firstPublished 2021
https://www.w3.org/2000/01/rdf-schema#label Pushed Authorization Requests
gptkbp:mechanismOfAction client receives request URI
request URI sent to authorization endpoint
authorization request sent directly to authorization server
gptkbp:publishedBy gptkb:IETF
gptkbp:purpose improve security of OAuth authorization requests
prevent authorization request tampering
support large authorization requests
gptkbp:relatedTo gptkb:OAuth_2.0_Authorization_Code_Flow
gptkb:OAuth_2.0_Security_Best_Current_Practice
gptkbp:status Proposed Standard
gptkbp:usedBy gptkb:OpenID_Connect
gptkb:Financial-grade_API_(FAPI)
gptkbp:usedIn gptkb:OAuth_2.0
gptkbp:bfsParent gptkb:RFC_9007
gptkbp:bfsLayer 7