There's also the RFC on OAuth2:
https://datatracker.ietf.org/doc/html/rfc6749
The introduction will give you a bit of a background. The most important to read (for now) is just the introduction up to chapter 2.
https://datatracker.ietf.org/doc/html/rfc6749
The introduction will give you a bit of a background. The most important to read (for now) is just the introduction up to chapter 2.
https://www.ietf.org/archive/id/draft-ietf-oauth-v2-1-09.htm...
From the spec:
"This Standards Track specification consolidates the information in all of these documents and removes features that have been found to be insecure..."