Internet Engineering Task Force (IETF)               T. Lodderstedt, Ed.
Request for Comments: 7009                           Deutsche Telekom AG
Category: Standards Track                                      S. Dronia
ISSN: 2070-1721
                                                            M. Scurtescu
                                                             August 2013

                       OAuth 2.0 Token Revocation


   This document proposes an additional endpoint for OAuth authorization
   servers, which allows clients to notify the authorization server that
   a previously obtained refresh or access token is no longer needed.
   This allows the authorization server to clean up security
   credentials.  A revocation request will invalidate the actual token
   and, if applicable, other tokens based on the same authorization

