How to use this reference
Document which component holds each credential, binds the user session, and enforces request destinations. Compare those responsibilities and residual risks against an owned application’s architecture.
Before reading
- OAuth client and resource-server roles
- Browser origins, cookies, and HTTP redirects
Context and limits
- Backend token custody does not make compromised application code harmless.
- Browser-specific guidance complements RFC 9700; it does not establish security of a particular deployment.
Sources and provenance
- RFC 10017: OAuth 2.0 for Browser-Based Applications Internet Engineering Task Force / RFC Editor · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.