...
We use https://github.com/xmlgrrl/UMA-Specifications for active spec development, with snapshots provided on the docs.kantarainitiative.org site. The UMA wiki page for the core spec summarizes breaking and notable changes to both the core spec and other normative specs.
The UMA technical specifications have reached Version 1.0 finalization. The normative specs include :
- User-Managed Access (UMA) Profile of OAuth 2.0 (latest version, pretty-printed) (most recent IETF I-D, possibly somewhat out of date wrt the KI version)
- OAuth 2.0 Resource Set Registration (latest version, pretty-printed) (most recent IETF I-D, possibly somewhat out of date wrt the KI version)
UMA has been made a full-fledged profile of OAuth, and over time it is incorporating (as well as spinning off) functionality that comes from the wider OAuth specification universe. The UMA core spec now refers to a resource set registration spec that was the final UMA Core V1.0 specification (Kantara Recommendation, IETF I-D rev 13) and the OAuth Resource Set Registration V1.0 specification (Kantara Recommendation, IETF I-D rev 06), dated 4 April 2015. The latter specification was originally derived from UMA design work, but is suitable for use by other OAuth-based technologies. It OAuth and OpenID Connect as well. UMA Core also refers to a binding obligations spec Binding Obligations spec that is "contractual" in nature, rather than technical. See the references in the core spec for the other referenced bits.
The following auxiliary documents are currently non-normative:
...
- User-Managed Access (UMA) Claim Profiles Framework (latest version, pretty-printed) (most recent IETF I-D, possibly somewhat out of date wrt the KI version)
- Claims 2.0 and Simple Access Authorization Claims (obsoleted by Claim Profiles, itself obsolete)
- Legal Considerations (obsoleted by Binding Obligations)
- Lexicon (obsoleted by the spec itself and Binding Obligations)
- UMA Trust Model (obsoleted by Binding Obligations)
- UMA User Stories (obsoleted by Case Studies)
- OAuth Dynamic Client Registration Protocol (obsoleted by the OAuth WG's own standards-track specification, to which UMA core now refers)
- UMA Resource Registration (obsoleted by the now spun-off OAuth Resource Set Registration spec)