References
Every specification and document the series relies on, grouped by subject.
Primary specifications and official project documentation, in one place. Each part links the ones it leans on; this is the full list.
OAuth and IETF
OAuth 2.1 Authorization Framework — Internet-Draft
As of September 2026, OAuth 2.1 is an active IETF Internet-Draft (draft-ietf-oauth-v2-1-16), not yet a published RFC.
- Datatracker: https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/
- HTML draft: https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1-16
OAuth 2.0 Authorization Framework — RFC 6749
Use primarily for historical/base OAuth 2.0 concepts. For modern security guidance, pair it with RFC 9700.
OAuth 2.0 Security Best Current Practice — RFC 9700 / BCP 240
Especially relevant for:
- Authorization Code security;
- refresh-token protection/rotation;
- redirect URI security;
- deprecated/insecure historical patterns;
- password-change security events.
PKCE — RFC 7636
Token Revocation — RFC 7009
Token Introspection — RFC 7662
Authorization Server Metadata — RFC 8414
JSON Web Token — RFC 7519
JSON Web Key — RFC 7517
JSON Web Signature — RFC 7515
OpenID Connect
OpenID Connect Core 1.0
Relevant for:
openidscope;- ID Tokens;
- claims;
- Authorization Code Flow;
- nonce;
- UserInfo.
OpenID Connect Discovery 1.0
Spring
Spring Security — Authorization Server
- https://docs.spring.io/spring-security/reference/servlet/oauth2/authorization-server/
- Getting started: https://docs.spring.io/spring-security/reference/servlet/oauth2/authorization-server/getting-started.html
Spring Authorization Server reference
Some documentation remains available under the standalone Spring Authorization Server reference tree:
- https://docs.spring.io/spring-authorization-server/reference/
- Configuration model: https://docs.spring.io/spring-authorization-server/reference/configuration-model.html
- Core model/components: https://docs.spring.io/spring-authorization-server/reference/core-model-components.html
- Protocol endpoints: https://docs.spring.io/spring-authorization-server/reference/protocol-endpoints.html
- UserInfo guide: https://docs.spring.io/spring-authorization-server/reference/guides/how-to-userinfo.html
When publishing code that uses Spring Security 7.x / Spring Boot 4.x, verify version-sensitive APIs against the matching Spring Security reference.