Skip to main content

The OAuth 2.1 Internet-Draft

OAuth 2.1 consolidates the framework agent tooling already depends on, replacing RFC 6749 and RFC 6750 and folding in a decade of security practice. It is still an active Internet-Draft. The Model Context Protocol requires authorization servers to implement it, so a large part of agent authorization rests on a document that is not yet an RFC.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0012
Kind
Draft in progress
Jurisdiction
Global
Last verified
Added
  • The draft states that it replaces and obsoletes the OAuth 2.0 Authorization Framework described in RFC 6749 and the Bearer Token Usage in RFC 6750.
  • The latest revision at the time of checking is draft-ietf-oauth-v2-1-16, dated 3 September 2026.
  • It remains an active Internet-Draft rather than a published RFC.
  • MCP authorization requires authorization servers to implement OAuth 2.1 for both confidential and public clients.

Dimension by dimension

1 dimension, each one stated, silent or open

Authorization. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

AuthorizationStated
It is the authorization baseline the agent tooling ecosystem cites, including mandatory PKCE and the removal of the implicit and password grants.IETF Datatracker, draft-ietf-oauth-v2-1, primary source, 3 September 2026.

What it changes

For a team deploying an agent

Your agent stack cites a draft. That is normal in this field and not a defect, but it belongs in your risk register: revision numbers move, and a control you wrote against draft 13 may read differently at draft 16. Pin the revision you implemented and re read it when you upgrade.

Sources

What this record was verified against

  1. IETF Datatracker, draft-ietf-oauth-v2-1Primary · 3 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0012 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), the oauth 2.1 internet-draft.
APA
GAGE (Global Academy of Generative-AI Education). (2026). The OAuth 2.1 Internet-Draft. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0012-oauth-2-1-internet-draft
MLA
"The OAuth 2.1 Internet-Draft." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0012-oauth-2-1-internet-draft.
Chicago
GAGE (Global Academy of Generative-AI Education). "The OAuth 2.1 Internet-Draft." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0012-oauth-2-1-internet-draft.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0012-oauth-2-1-internet-draft

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every draft in progress record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.