I couldn't keep track of all the RFCs related to OAuth. So here they are.
- [The OAuth 2.0 Authorization Framework][1]
- [Proof Key for Code Exchange by OAuth Public Clients][2]
- [OAuth 2.0 for Native Apps][3]
- [OAuth 2.0 Device Authorization Grant][4]
These RFCs underly the OAuth.
- [JSON Web Token (JWT)][5]