---
type: "Specification"
title: "OAuth 2.0 Security BCP — RFC 9700"
description: "Current best practice; deprecates insecure OAuth modes."
resource: "https://www.rfc-editor.org/rfc/rfc9700"
tags: [oauth, security, bcp]
generated: { by: human:crpage, at: 2026-07-09T09:44:00Z }
status: stable
sources: [{ id: primary, resource: "https://www.rfc-editor.org/rfc/rfc9700" }]
---

Updates the OAuth threat model and security advice and deprecates modes now considered insecure. Underpins the move from bearer access toward demonstrable, sender-constrained authority.

# Terms
Glossary terms used here: [Bearer token](../glossary/bearer-token.md).
