Skip to main content

RFC 6749, the OAuth 2.0 authorization framework

Published in October 2012, this is the grammar every agent authority scheme still speaks. It lets a third party application obtain limited access to a service on behalf of a resource owner, by arranging an approval interaction rather than handing over the owner's password. Agent authorization in 2026 is mostly this framework with narrower audiences.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0007
Kind
Standard or protocol
Jurisdiction
Global
Last verified
Added
  • The framework enables a third party application to obtain limited access to an HTTP service on behalf of a resource owner, or on its own behalf.
  • It separates the resource owner, the client, the authorization server and the resource server, which is the separation every agent scheme reuses.
  • It is a framework rather than a protocol, which is why later documents such as RFC 8707 and the OAuth 2.1 draft exist to close its options.
  • The client credentials grant it defines is the path most autonomous agents take when no human is present.

Dimension by dimension

2 dimensions, each one stated, silent or open

Authorization, Delegation. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

AuthorizationStated
Access is a scoped token issued by an authorization server, never the resource owner's own credential.RFC Editor, RFC 6749, primary source, 1 October 2012.
DelegationSilent
A resource owner approving a client is delegation, but the framework models one hop only and says nothing about an agent that calls another agent.RFC Editor, RFC 6749, primary source, 1 October 2012.

What it changes

For a team deploying an agent

Your agent almost certainly holds an OAuth token. That means the questions an auditor will ask are old ones: which grant, which scopes, which audience, how long lived, and who can revoke it. If your team cannot answer those for the agent, the agent has no authorization story at all.

Sources

What this record was verified against

  1. RFC Editor, RFC 6749Primary · 1 October 2012

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0007 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), rfc 6749, the oauth 2.0 authorization framework.
APA
GAGE (Global Academy of Generative-AI Education). (2026). RFC 6749, the OAuth 2.0 authorization framework. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0007-rfc-6749-oauth-2-0-authorization-framework
MLA
"RFC 6749, the OAuth 2.0 authorization framework." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0007-rfc-6749-oauth-2-0-authorization-framework.
Chicago
GAGE (Global Academy of Generative-AI Education). "RFC 6749, the OAuth 2.0 authorization framework." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0007-rfc-6749-oauth-2-0-authorization-framework.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0007-rfc-6749-oauth-2-0-authorization-framework

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every standard or protocol record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.