%% You should probably cite rfc8693 instead of this I-D. @techreport{ietf-oauth-token-exchange-03, number = {draft-ietf-oauth-token-exchange-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-token-exchange/03/}, author = {Michael B. Jones and Anthony Nadalin and Brian Campbell and John Bradley and Chuck Mortimore}, title = {{OAuth 2.0 Token Exchange: An STS for the REST of Us}}, pagetotal = 28, year = 2015, month = dec, day = 14, abstract = {This specification defines a protocol for a lightweight HTTP- and JSON- based Security Token Service (STS) by defining how to request and obtain security tokens from OAuth 2.0 authorization servers, including security tokens employing impersonation and delegation.}, }