What IETF RFC 7009 - OAuth 2.0 Token Revocation: Explicit Token Invalidation Protocol requires
RFC 7009 defines the OAuth 2.0 Token Revocation endpoint protocol allowing clients to notify the authorization server that a previously obtained token (access token or refresh token) is no longer needed, enabling logout flows, compromised token invalidation, and session termination in OAuth-based systems without waiting for natural token expiry.
Pillar: Workflow Automation · Authority: Internet Engineering Task Force (IETF) - OAuth Working Group · Version: 2013-08 · Last updated:
Primary source: https://www.rfc-editor.org/rfc/rfc7009
SHA-256 integrity: 99db5475a21474ba8feca7283b289f76527c8c9a35bd298701ff789140549c7d
Primary Citations — 6 traced to source
- Section 2 - Token Revocation; Section 2.1 - Revocation Request; Section 2.2 - Revocation Response — RFC 7009 - OAuth 2.0 Token Revocation (August 2013)
- Section 2 - revocation_endpoint metadata discovery — RFC 8414 - OAuth 2.0 Authorization Server Metadata (June 2018)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/ietf-rfc-7009-oauth-2-0-token-revocation-2013.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/ietf-rfc-7009-oauth-2-0-token-revocation-2013.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/ietf-rfc-7009-oauth-2-0-token-revocation-2013
- Back to registry: Browse all 10,099 compliance nodes