OAuth 2.0 Token Revocation
OAuth 2.0 Token Revocation
复制标题
OAuth 2.0 令牌撤销
DOI:
10.17487/rfc7009
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Marius Scurtescu
中科院分区:
文献类型:
--
作者:
T. Lodderstedt;Stefanie Dronia;Marius Scurtescu
This document proposes an additional endpoint for OAuth authorization
servers, which allows clients to notify the authorization server that
a previously obtained refresh or access token is no longer needed.
This allows the authorization server to clean up security credentials.
A revocation request will invalidate the actual token and, if
applicable, other tokens based on the same authorization grant.