As mentioned elsewhere, I'd probably start with OAuth2.1 (not quite a standard but well on its way) as this updates the OAuth2 standard, as well as consolidates lots of improvements.
https://www.ietf.org/archive/id/draft-ietf-oauth-v2-1-09.htm...
https://www.ietf.org/archive/id/draft-ietf-oauth-v2-1-09.htm...
From the spec:
"This Standards Track specification consolidates the information in all of these documents and removes features that have been found to be insecure..."