Profile for Justin Richer Skip to main content Datatracker Groups By area/parent Apps & Realtime General Internet Ops & Management Routing Security Web and Internet Transport IESG IAB IRTF IETF LLC RFC Editor Other Active AGs Active Areas Active Directorates Active IAB Workshops Active Programs Active RAGs Active Teams New work Chartering groups BOFs BOF Requests Other groups Concluded groups Non-WG lists Documents Search Recent I-Ds Submit an Internet-Draft RFC streams IAB IRTF ISE Editorial Subseries STD BCP FYI Meetings Agenda Materials Floor plan Registration Important dates Request a session Session requests Upcoming meetings Upcoming meetings Past meetings Past meetings Meeting proceedings Other IPR disclosures Liaison statements IESG agenda NomComs Downref registry Statistics I-Ds/RFCs Meetings API Help Release notes System status Report a bug User Sign in Password reset Preferences New account List subscriptions IETF Lists IRTF Lists IAB Lists RFC-Editor Lists Report a bug Sign in Javascript disabled? Like other modern websites, the IETF Datatracker relies on Javascript. Please enable Javascript for full functionality. Justin Richer Pronouns: he/him Justin Richer Justin Richer is a security architect, software engineer, standards editor, and systems designer with over two decades of industry experience. He is the lead author of the book "OAuth2 In Action" and contributor to OAuth 2.0 and OpenID Connect. Justin is the editor of a variety of standards including GNAP (RFC9635, RFC9767), HTTP Message Signatures (RFC9421), Vectors of Trust (RFC8485), and OAuth extensions for dynamic client registration (RFC7591, RFC7592), token introspection (RFC7662), and rich authorization requests (RFC9396). Justin is a co-author to US government standards NIST SP 800-63, FIPS201, and NIST SP 800-217. Roles Role Group Email Chair Workload Identity in Multi System Environments (wimse) jricher@mit.edu External Resources Name Value GitHub Username jricher Additional Web Page https://bspk.io/ RFCs (8) RFC Date Title Cited by RFC 7591 Jul 2015 OAuth 2.0 Dynamic Client Registration Protocol 16 RFCs RFC 7592 Jul 2015 OAuth 2.0 Dynamic Client Registration Management Protocol 1 RFC RFC 7662 Oct 2015 OAuth 2.0 Token Introspection 14 RFCs RFC 8485 Oct 2018 Vectors of Trust RFC 9396 May 2023 OAuth 2.0 Rich Authorization Requests 3 RFCs RFC 9421 Feb 2024 HTTP Message Signatures 3 RFCs RFC 9635 Oct 2024 Grant Negotiation and Authorization Protocol (GNAP) 1 RFC RFC 9767 Apr 2025 Grant Negotiation and Authorization Protocol Resource Server Connections 1 RFC Active Internet-Drafts (1) draft-richer-oauth-httpsig Expired Internet-Drafts (25) draft-richer-oauth-tmb-claim draft-richer-oauth-pushed-client-registration draft-ietf-oauth-pop-architecture draft-richer-wimse-token-container draft-gilman-wimse-use-cases draft-richer-oauth-json-request draft-maler-oauth-umafedauthz draft-maler-oauth-umagrant draft-bradley-oauth-stateless-client-id draft-ietf-oauth-signed-http-request draft-ietf-oauth-dyn-reg-metadata draft-ietf-oauth-v2-http-mac draft-richer-oauth-dyn-reg-management draft-richer-oauth-chain draft-richer-oauth-xml draft-richer-oauth-instance (Excluding replaced Internet-Drafts.) Internet-Draft Activity IETF IESG IAB IRTF IETF LLC IETF Trust RFC Editor IANA Privacy Statement About IETF Datatracker Version 12.69.0 (release - 3cce873) System Status Report a bug: GitHub Email