OAuth 2.1

OAuth 2.1 vs OAuth 2.0

Since the publication of the OAuth 2.0 Authorization Framework (RFC6749) in October 2012, it has been updated by OAuth 2.0 for Native Apps (RFC8252), OAuth Security Best Current Practice (also for Bearer Token Usage), and OAuth 2.0 for Browser-Based Apps.

OAuth 2.1 is compatible with OAuth 2.0 with the extensions and restrictions from OAuth Security Best Current Practice applied.

Key Advantages of OAuth 2.1:

Key Challenges of OAuth 2.1: