OAuth 2.0 Framework — RFC 6749
Threat Model and Security Considerations — RFC 6819
OAuth Assertions Framework — RFC 7521
SAML2 Bearer Assertion — RFC 7522, for integrating with existing identity systems
JWT Bearer Assertion — RFC 7523, for integrating with existing identity
OAuth 2.0 Protocol Detailed Walkthrough
Explicit Logout from IdentityServer4
Using existing DB with IdentityServer4