IETF · April 2025
GNAP Resource Server Connections
RFC 9767
J. Richer (ed.), F. Imbault
RFCStableAuthorizationAdjacent
Completes the GNAP picture the way RFC 9728 completes OAuth's.
At a glance
- Problem
- GNAP core needed a standard way for resource servers to connect to authorization servers (introspection-like, token discovery, well-known gnap-as-rs).
- Identity / authn / authz
- Authorization infrastructure for GNAP deployments.
Actors
- Resource server
- Authorization server
When this matters for agents
When this matters for agents: only if you are actually deploying GNAP. Completes the GNAP picture the way RFC 9728 completes OAuth's. Skip it on an OAuth/MCP path.
Flow in plain language
RS discovers AS RS-facing metadata and presents tokens for validation / continuation as specified.
Implementer notes
Read only if you are actually deploying GNAP.
Relationship to others
Primary sources
- RFC 9767https://www.rfc-editor.org/rfc/rfc9767.html