How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
The OAuth 2.0 Standard cover

API Evangelist Paper · Standard Report

The OAuth 2.0 Standard

775 published contracts still declare the implicit flow — 28.9% of every OAuth-using contract in the corpus, for a flow removed from OAuth 2.1.

$500.00 Version 1.0 · July 2026
picture_as_pdf Formatted PDF, ~29 pages
description Editable Microsoft Word (.docx)
database The AI data bundle — every provider, scored (JSON/CSV/YAML)
update Free updates to this paper, for life
lock Secure checkout via Stripe

About this paper

OAuth 2.0 is fifteen years old, it won completely, and it is the substrate beneath OpenID Connect, every open-banking regime and every agent acting on someone’s behalf. This report measured what 14,195 published API contracts actually declare about it.

775 of them declare the implicit flow — 28.9% of every OAuth-using contract in the corpus — for a flow formally discouraged for years and removed entirely from OAuth 2.1. Seventy-two more declare the password grant. But the breakdown tells you it is not defiance: 562 of the 775 are Swagger 2.0 documents written before the guidance existed and never revisited. The finding is not that the industry ignores security advice. It is that a security contract, once written, is never re-read, and nothing in any toolchain looks at it.

Alongside that: scopes, the entire point of OAuth, are declared by 15.3% of documents. 815 contracts put an API key in the query string, and 178 declare an authorization server nobody can reach. The endpoints that do work resolve to a handful of identity platforms who already hold the scope definitions and could move every number here without persuading anyone.

What's inside

  1. Executive summary — the 775
  2. What OAuth 2.0 is, and what it is not
  3. What the corpus declares
  4. The flows — and the 775
  5. Scopes — the point of OAuth, mostly unstated
  6. The blueprint
  7. Agents — why a loose OAuth declaration became a live risk
  8. The regulatory layer
  9. The scoring caveat and the limits
  10. What would have to be true
  11. The investable thesis
  12. Where this is going

database Includes the AI data bundle

This report ships with a machine-readable data bundle — the evidence behind every number, packaged to drop straight into the AI tool of your choice. Converse with the research you bought, check any claim against the source data, and take it further than the PDF.

data_object providers.json / .csv / .yaml — every provider, layered raw → enriched → derived
table_rows scores.csv & rankings.csv — facet-by-facet scores, composite vs. agent-readiness rank
insights market-stats.json & capabilities.json — sector averages, band distribution, per-provider artifact inventory
forum AI-START-HERE + data dictionary, methodology & prompts — a paste-in primer so your AI reads it correctly

folder_zip Delivered as a single ZIP alongside your PDF and Word edition at checkout.

What you get for $500.00

picture_as_pdf A print-ready, formatted PDF edition
description The editable Word (.docx) source
database The AI data bundle — every provider scored, as JSON/CSV/YAML
forum An AI conversation primer so you can query the research directly
checklist The anti-patterns & self-assessment checklist
update Every future revision of this living paper
$500.00 PDF + Word + AI data bundle (ZIP), instant download

These papers are experience-based and vendor-neutral, distilled from the API Evangelist research at apievangelist.com. Questions before buying? [email protected].

arrow_back All papers