ietf-corpus

rfc-8252

OAuth 2.0 for Native Apps

W. Denniss, J. Bradley
date2017-10 streamIETF areasec wgoauth statusBEST CURRENT PRACTICE pages21 canonicalhttps://www.rfc-editor.org/rfc/rfc8252 doi10.17487/RFC8252 errataview
OAuth 2.0 authorization requests from native apps should only be made through external user-agents, primarily the user's browser. This specification details the security and usability reasons why this is the case and how native apps and authorization servers can implement this best practice.

updates

also