I am implementing Personal Access Tokens for an application I am working on. This would be similar to Personal Access Tokens generated by GitHub or BitBucket. I was wondering if there is an RFC or specification that exists for these kind of access control. I was able to find some related but this doesn't seem to be related to oAuth as in oAuth we require a 2 way handshake to achieve this.