Hacker News new | ask | show | jobs
by UncleMeat 2979 days ago
Yep. I'm fairly concerned about an identity management company publishing this information.
1 comments

Author here -

Entirely agree and we recommend using Auth Code+PKCE whenever possible. This post is intended to be the first of a few starting with the base spec. In the next one, I plan to go over the RFCs for JWT, Revocation, Inspection, PKCE, the AppAuth pattern, and probably a few others.

Thanks for the note though.

Thanks for the shoutout to AppAuth (https://appauth.io). It’s our 20% project at Google.