vulns.co
/
GKData.io MCP

Internet Engineering Task Force / RFC Editor · 1 min read

RFC 10017: OAuth 2.0 for Browser-Based Applications

Compares browser-only OAuth clients, token-mediating backends, and backend-for-frontend architectures through their different token-custody and session boundaries. Separates protection of token material from the residual authority of compromised same-origin application code.

Open the reference Technical StandardReviewed 2026-10-03

How to use this reference

Document which component holds each credential, binds the user session, and enforces request destinations. Compare those responsibilities and residual risks against an owned application’s architecture.

Before reading

  • OAuth client and resource-server roles
  • Browser origins, cookies, and HTTP redirects

Context and limits

  • Backend token custody does not make compromised application code harmless.
  • Browser-specific guidance complements RFC 9700; it does not establish security of a particular deployment.

Sources and provenance

  1. RFC 10017: OAuth 2.0 for Browser-Based Applications Internet Engineering Task Force / RFC Editor · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software