RFC 9700 Security Audit: How New OAuth Mandates Expose Critical Vulnerabilities in UPS, FedEx and DHL API Integrations
In January 2025, the IETF published RFC 9700: Best Current Practice for OAuth 2.0 Security. This update fundamentally changes how OAuth 2.0 implementations must handle security, with RFC 9700 now mandating PKCE for all client types, including server side apps. For carrier API integrations already struggling with authentication