OAuth 2.0 is the industry-standard protocol for authorization. OAuth 2.0 focuses on client developer simplicity while providing specific authorization flows for web applications, desktop applications, mobile phones, and living room devices. This specification and its extensions are being developed within the IETF OAuth Working Group.
Questions, suggestions and protocol changes should be discussed on the mailing list.
The specs below are either experimental or in draft status and are still active working group items. They will likely change before they are finalized as RFCs or BCPs.