Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC8252
Discuss this RFC: Send questions or comments to the mailing listoauth@ietf.org
Other actions:View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 8252
OAuth 2.0 authorization requests from native apps should only be madethrough external user-agents, primarily the user's browser. Thisspecification details the security and usability reasons why this isthe case and how native apps and authorization servers can implementthis best practice.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.