<?xml version='1.0' encoding='UTF-8'?>

<reference anchor='I-D.barnes-oauth-model'>
<front>
<title>The OAuth Security Model for Delegated Authorization</title>

<author initials='R' surname='Barnes' fullname='Richard Barnes'>
    <organization />
</author>

<author initials='M' surname='Lepinski' fullname='Matt Lepinski'>
    <organization />
</author>

<date month='July' day='8' year='2009' />

<abstract><t>This document describes the security model for the OAuth authorization system, which allows a party that holds some authorization to delegate a subset of that authorization to another party, without requiring either party to disclose its credentials to the other.  In this document, we describe a set of design constraints, a high-level work flow for establishing authorizations subject to those constraints, and set of security requirements for protocols that implement this model.</t></abstract>

</front>

<seriesInfo name='Internet-Draft' value='draft-barnes-oauth-model-01' />
<format type='TXT'
        target='http://www.ietf.org/internet-drafts/draft-barnes-oauth-model-01.txt' />
</reference>

