Client types
Public clients cannot safely hold a secret; confidential clients protect credentials in a backend or workload boundary.
DEVELOPER
Use Authorization Code + PKCE for user-facing clients, confidential credentials only where a protected backend exists, narrow scopes and controlled token lifecycle.
Public clients cannot safely hold a secret; confidential clients protect credentials in a backend or workload boundary.
Authorization Code + PKCE with state; OIDC clients validate issuer, audience and nonce where applicable.
Keep access tokens short-lived, protect refresh tokens, revoke on compromise and never log bearer tokens.
Match registered redirect URIs exactly in production; avoid open redirects and wildcard hosts.
OAuth safety depends on the registered client type, exact redirects, PKCE/nonce handling, token storage, revocation and scope policy for the deployed application.