Specs
Drafts I'm working on, mostly at the seam between the OAuth stack and OpenID AuthZEN. The title links to the live text, and alongside it is the Internet-Draft each one continues.
AuthZEN Profile for OAuth 2.0 Token Issuance
Every OAuth specification that defines a token issuance moment declares the decision itself to be local policy, out of scope. So the most security-relevant step in issuance has no interoperable expression. This profiles the OpenID AuthZEN Authorization API for that moment, casting the authorization server as a policy enforcement point: how the inputs map onto AuthZEN's mandatory five-tuple, how a decision may narrow the issued token but never broaden it, and how the two sides discover each other.
AuthZEN Binding for OAuth 2.0 Token Exchange
RFC 8693 defines the moment an authorization server decides whether one party may obtain a token to act as, or on behalf of, another, and declines to define the policy that governs it. This binds the whole family that inherits that seam - token exchange itself, identity chaining, identity assertion authorization grants and transaction tokens - to the issuance profile, treating the requesting party's authority as a decision distinct from the authority being delegated.
AuthZEN Profile for Authorization Claims in JWT Access Tokens
RFC 9068 says a JWT access token should carry the subject's groups, roles and entitlements, and says nothing about where they come from. These are enumerations rather than decisions, and AuthZEN has an operation built for them. This binds each claim to a Resource Search the authorization server issues itself: which action name and resource type, what the claim looks like when the result set is empty, and why a search result may never influence whether a token is issued.
All three were adopted by the OpenID AuthZEN working group in August 2026 and live in openid/authzen. Disagreements are best filed there as issues or pull requests.