IETF RFC 7009
OAuth 2.0 Token Revocation
Organization: | IETF |
Publication Date: | 1 August 2013 |
Status: | active |
Page Count: | 10 |
scope:
This document proposes an additional endpoint for OAuth authorization servers, which allows clients to notify the authorization server that a previously obtained refresh or access token is no longer needed. This allows the authorization server to clean up security credentials. A revocation request will invalidate the actual token and, if applicable, other tokens based on the same authorization grant.
Document History
