You have a little typo in the abstract:"bearer tokens must to be protected from disclosure in transit and at rest."
I think you mean "must be protected" - Mike ------------------------------------- Michael Schwartz Gluu Founder / CEO m...@gluu.org _______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth