# GNAP: A Proposed Authorization Protocol Related to OAuth 2.0 and OpenID Connect

DevFeed: [GNAP: A Proposed Authorization Protocol Related to OAuth 2.0 and OpenID Connect](<https://devfeed.tech/articles/gnap-the-next-generation-of-oauth-43354.md>)

Original publisher: [Read original article](<https://fusionauth.io/blog/gnap-next-gen-oauth>)

Author: Dan Moore

Published: 2021-01-07T00:00:00Z

Content type: article

Language: en

Sources: [FusionAuth](<https://devfeed.tech/sources/fusionauth-blog.md>)

Topics: [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [standard](<https://devfeed.tech/topics/standard.md>), [Internet Engineering Task Force (IETF)](<https://devfeed.tech/topics/ietf.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [education](<https://devfeed.tech/tags/education.md>), [ietf](<https://devfeed.tech/tags/ietf.md>), [negotiation](<https://devfeed.tech/tags/negotiation.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [security](<https://devfeed.tech/tags/security.md>), [standard](<https://devfeed.tech/tags/standard.md>)

## AI overview

This article introduces GNAP, an authorization protocol being developed by an IETF working group. It explains that GNAP is not backward compatible with OAuth 2.0 or OpenID Connect, while targeting related problems such as fine-grained delegation, API access, user identifiers, and identity assertions.

## Source excerpt

GNAP (Grant Negotiation and Authorization Protocol) is a next-gen auth standard under development. Learn how it differs from OAuth2 and why it matters.