OAuth 2.0 is the industry-standard protocol for authorization. OAuth 2.0 focuses on client developer simplicity while providing specific authorization flows for web applications, desktop applications, mobile phones, and living room devices. This specification and its extensions are being developed within the IETF OAuth Working Group.
OAuth 2.1 is an in-progress effort to consolidate OAuth 2.0 and many common extensions under a new name.
Questions, suggestions and protocol changes should be discussed on the mailing list.
These specs are used to add additional security properties on top of OAuth 2.0.
The specs below are either experimental or in draft status and are still active working group items. They will likely change before they are finalized as RFCs or BCPs.