Status board
Finished, still a draft, or only a program.
Vendors blur these. A draft is something you can build against. A Recommendation is something you can put in a contract. A program that hasn’t published a standard yet is just a program. Here’s where things sit on 2 October 2026.
Board
| Specification | Status | What to do with it |
|---|---|---|
| OAuth 2.1 draft-ietf-oauth-v2-1-16 |
Working group draft 3 September 2026. Milestone to send to the IESG in December 2026. Expires 7 March 2027 if it is not refreshed. Not an RFC. |
Build the code flow with S256 PKCE. Drop implicit and the password grant. Match redirect URIs exactly, and keep bearer tokens out of query strings. Public clients should rotate refresh tokens, or bind them to a key. Draft 16 also kills PKCE plain and makes the authorization server return iss. Flow. |
| OAuth 2.0 Security BCP RFC 9700 |
Best current practice January 2025. |
This is the security doc OAuth 2.1 is rolling up. If a platform still speaks OAuth 2.0, follow 9700 anyway. The attacks didn’t wait for a new RFC number. |
| OpenID Connect Core 1.0 | Final This is what a modern login actually is. |
The ID token is the login. Check iss, aud, exp, nonce, and the signature. An access token doesn’t tell you who the user is. Flow. |
| PKCE RFC 7636 |
RFC 2015. Required for every code flow in the OAuth 2.1 draft. |
Use S256. Keep the verifier on the client that will redeem the code. Draft 16 of OAuth 2.1 drops the plain method, which almost nobody should have been using. |
Authorization response issRFC 9207 |
RFC March 2022. Required from the authorization server in OAuth 2.1 draft 16. |
Compare iss on the redirect with the issuer you meant to talk to. Matters once a client knows more than one authorization server. |
| DPoP RFC 9449 |
RFC September 2023. |
Stick the access token to a key the client holds, and send a fresh proof on each call. The MCP TypeScript SDK picked this up in the 2.1.0 release, late September 2026. Flow. |
| Token exchange RFC 8693 |
RFC January 2020. |
Trade a broad token for a narrower one, and put the software that actually called in the act claim. That’s the shape you want when an agent does one task against one API. Flow. |
| WebAuthn Level 3 | W3C Recommendation 25 August 2026. No substantive changes after the 26 May 2026 Candidate Recommendation. |
This is the passkey API to cite. It covers registration, sign-in, and the origin binding, plus the bits browsers already ship: JSON helpers, capability detection, conditional create, related origins, the signal methods, and PRF. Flow. |
| WebAuthn Level 4 | First Public Working Draft 15 September 2026. Charter expects a Recommendation in the fourth quarter of 2028. |
Keep an eye on it. First drafts move. Don’t point a contract at this one. |
| SAML 2.0 | OASIS standard Still the default in a lot of workforce SaaS catalogs. |
Sign the assertion. Check audience, recipient, the time window, and InResponseTo. New apps can speak OpenID Connect. Keep a tested SAML path for the ones that don’t. Flow. |
| SCIM 2.0 RFC 7643 and RFC 7644 |
RFC | Push joiners, movers, and leavers. The leaver is the actual control: active: false, or a delete. And treat the SCIM bearer token like the admin credential it is. Flow. |
| SPIFFE and SPIRE | CNCF specifications Workload identity for services. |
Give the process a document it can prove, instead of a secret someone copied into a repo. OAuth client credentials is the same idea, aimed at an HTTP API. Flow. |
| MCP authorization | Spec · 28 Jul 2026 Current protocol revision. Authorization is optional. When a server requires it, the server is an OAuth resource server and the MCP client is an OAuth client. |
Code flow plus PKCE, and find the authorization server from the protected-resource metadata. Check iss on the redirect when it’s there. Prefer client ID metadata documents. This revision deprecates dynamic client registration. The TypeScript SDK 2.1.0 release, late September 2026, adds DPoP, which is worth turning on. |
| NIST SP 800-207 Zero Trust Architecture |
Published August 2020. People say “zero trust” and mean this. |
Decide on the specific request, in context, and keep deciding. The hard part now is service accounts and the apps that never joined the IdP. Flow. |
| NIST AI Agent Standards Initiative and the NCCoE identity project |
Program Initiative announced 17 February 2026. Concept paper in February, public comment through 2 April, more than 600 responses. The project hub is a demonstration, not a published standard. |
Don’t sit on a design waiting for a new agent protocol. Use OAuth, OpenID Connect, SCIM, and workload identity. Every agent grant wants an owner, an actor claim, a scope, and an expiry. Flow. |
How to read the chips
Stable means you can require it: a Recommendation, an RFC, a finished spec. Draft means the IETF is still editing, even when every serious product already behaves this way. Early is a first public draft. Interesting, and too soon for a contract. Program means someone started a standards effort and hasn’t written the document yet.
The names link to the source. The home page is the same news, written out.