Hacker News new | ask | show | jobs
by distalx 324 days ago
Spot on. The burden and complexity of that cryptographic signing on the client is exactly what OAuth2 was created to avoid. Thanks for making that connection.