Audit in OAuth 2.0
Zhanna Tsitkov · 2015
This specification is an effort to provide guidelines for implementing the Audit functionality for OAuth 2.0 enabled environments. The data of interest for the OAuth 2.0 audit includes scopes, permissions, policies and other authorization and authentication related information. It can be used by resource and authorization servers for detecting security-related problems in real time and fast violation response, or by government agencies and various institutions for after-the-fact forensic and compliance analysis.