OAuth Security Workshop (OSW)
- Next edition
- Not yet announced
- Where
- Changes each year (Leipzig in 2026)
- Usually
- Spring, varies by year
- Format
- In-Person
- Organizer
- OSW organizing committee
- Cost
- €450 (2026)
Editions
- May 27 to 29, 2026 · Design Offices, Augustusplatz 1-4, Leipzig, Germany · concluded
What this conference is for
The OAuth Security Workshop (OSW) is the most technical event on this list. It began in November 2015 in Darmstadt, Germany, hosted by Deutsche Telekom, after researchers independently found attacks on OAuth and OpenID Connect. It has since become the place where protocol attacks and their fixes are worked through by the people who write the specs, the academics who break them, and the engineers who ship them. Much of the thinking behind the OAuth security best current practice and OAuth 2.1 was argued out here.
Who should attend
Protocol designers, standards contributors, security researchers, and identity engineers who implement authorization servers or clients. This is not an introduction; come knowing PKCE, token binding, and the OAuth threat model.
What to expect
Pre-submitted, peer-reviewed sessions combined with a barcamp-style unconference. On-site participation is required. The host city changes each year: recent editions were in Reykjavik (2025) and Leipzig (2026, the 11th), where registration was €450.
Coverage
We cover OSW in full because it shapes the standards our readers implement. The 2027 host and dates have not been announced; this page will update when they are.
Related on Start with Identity
- PodcastAuth0
The late Vittorio Bertocci's interviews with the authors of OAuth, OpenID Connect, FIDO, and SAML. Ended in 2022, and still the best audio archive on identity s
- CVEDrupal Simple OAuth/OIDC auth bypass via an alternate path
Drupal Simple OAuth / OIDC 6.0.0 through 6.0.6 allowed authentication to be skipped on an alternate path. Patched in 6.0.7.
- CVEDuende OAuth token management mixes tokens across requests
A race in Duende's .NET OAuth token-management package could attach client A's token to client B's request. Session mix-up, not a crypto break, but it is still
- GlossaryOAuth 2.0
OAuth 2.0 is the standard authorization framework for delegated access. It lets a client obtain limited access to a resource owner's data without handling their
- CVEOAuth 2.0 private_key_jwt audience ambiguity
A specification-level flaw in the OAuth 2.0 JWT profile: private_key_jwt audience is ambiguous, so a token minted for one authorization server can be accepted b
- GlossaryAccess Token
A short-lived credential a client presents to a resource server to access protected data. Access tokens are typically opaque or JWT-formatted, with lifetimes me