Spring Authorization Server moving to Spring Security 7.0 Skip to main content Learn more about Day 0 access to security patches via Enterprise support. Why Spring Overview Trending Generative AI Cloud Architecture Patterns Microservices Reactive Event Driven Application Types Web Applications Serverless Batch Learn Getting Started Quickstart Guides Academy Courses Get Certified Projects Overview Projects Spring Boot Spring Framework Spring Cloud Spring AI Spring Data Spring Integration Spring Batch Spring Security Foundational Projects Micrometer Reactor Development Tools Spring Tools Spring Initializr Resources Blog Release Calendar Version Mappings Release Highlights Security Advisories GitHub Orgs Spring Projects Spring Cloud Community Overview Events Authors Enterprise Overview Long-term Support Automated Upgrades Governance and Compliance Modern App Development Spring Blog RSS feeds All Posts Engineering Releases News & Events Spring Authorization Server moving to Spring Security 7.0 Engineering | Joe Grandja | September 11, 2025 | 1 min read | ... Spring Authorization Server has come a long way since 1.0 was officially released in November 2022. Starting as a project separate from Spring Security, has allowed it to iterate quickly on feature development and ultimately grow a rich feature set for building OAuth2 Authorization Servers. It has reached that point of maturity and stability and we believe the time is now to move it to Spring Security 7.0. The main benefit this will provide our users is a streamlined developer experience. Whether you are working with OAuth2 Client or OAuth2 Authorization Server, you won’t need to switch between projects any longer as the source, javadoc and reference documentation will live in Spring Security. Furthermore, issues and pull requests will be solely managed within Spring Security GitHub repository for all of the OAuth2 features. We also expect the migration impact to be quite minimal for our users as the maven coordinates, groupId and artifactId, will remain the same with the exception of the version. For example, the Spring Security 7.0 maven coordinates will be org.springframework.security:spring-security-oauth2-authorization-server:7.0.0. Also, the existing classes will remain the same in name and package location with the exception of a couple of minor package relocation changes that we’re confident will be a straightforward migration update. We hope you’re excited as we are as we prepare to move Spring Authorization Server to Spring Security 7.0. Get the Spring newsletter Stay connected with the Spring newsletter Subscribe Get ahead VMware offers training and certification to turbo-charge your progress.Learn moreGet support Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.Learn moreUpcoming events Check out all the upcoming events in the Spring community.View all Why Spring Generative AI Microservices Reactive Event Driven Cloud Web Applications Serverless Batch Learn Quickstart Guides Courses Get Certified Projects Resources Blog Release Calendar Version Mappings Release Highlights Security Advisories Community Events Authors Enterprise Long-term Support Automated Upgrades Governance and Compliance Modern App Development Thank You Copyright © 2005 - 2026 Broadcom. All Rights Reserved. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries. Terms of Use • Privacy • Trademark Guidelines Apache®, Apache Tomcat®, Apache Kafka®, Apache Cassandra™, and Apache Geode™ are trademarks or registered trademarks of the Apache Software Foundation in the United States and/or other countries. Java™, Java™ SE, Java™ EE, and OpenJDK™ are trademarks of Oracle and/or its affiliates. Kubernetes® is a registered trademark of the Linux Foundation in the United States and other countries. Linux® is the registered trademark of Linus Torvalds in the United States and other countries. Windows® and Microsoft® Azure are registered trademarks of Microsoft Corporation. “AWS” and “Amazon Web Services” are trademarks or registered trademarks of Amazon.com Inc. or its affiliates. All other trademarks and copyrights are property of their respective owners and are only mentioned for informative purposes. Other names may be trademarks of their respective owners.