# oauth-security-workshop

Source: https://startwithidentity.com/conferences/oauth-security-workshop/
Last updated: 2026-09-30
License: content by Start with Identity. Cite the source URL.

---

## What this conference is for

The OAuth Security Workshop (OSW) is the most technical event on this list. It began in November 2015 in Darmstadt, Germany, hosted by Deutsche Telekom, after researchers independently found attacks on [OAuth](https://startwithidentity.com/standards/oauth-2-0/) and [OpenID Connect](https://startwithidentity.com/standards/openid-connect/). It has since become the place where protocol attacks and their fixes are worked through by the people who write the specs, the academics who break them, and the engineers who ship them. Much of the thinking behind the OAuth security best current practice and [OAuth 2.1](https://startwithidentity.com/standards/oauth-2-1/) was argued out here.

## Who should attend

Protocol designers, standards contributors, security researchers, and identity engineers who implement authorization servers or clients. This is not an introduction; come knowing [PKCE](https://startwithidentity.com/glossary/pkce/), token binding, and the OAuth threat model.

## What to expect

Pre-submitted, peer-reviewed sessions combined with a barcamp-style unconference. On-site participation is required. The host city changes each year: recent editions were in Reykjavik (2025) and Leipzig (2026, the 11th), where registration was €450.

## Coverage

We cover OSW in full because it shapes the standards our readers implement. The 2027 host and dates have not been announced; this page will update when they are.
