RFC 8252: OAuth 2.0 for Native Apps
In plain English — editorial summary, not part of the RFC
OAuth 2.0 authorization requests from native apps should only be made through external user-agents, primarily the user's browser. This specification details the security and usability reasons why this is the case and how native apps and authorization servers can implement this best practice.
Document record
- Document ID
- RFC8252
- Published
- October 2017
- Authors
- W. Denniss; J. Bradley
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- sec
- Pages
- 21
- Also known as
- BCP212
- Updates:
- RFC 6749
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8248Security Automation and Continuous Monitoring (SACM) RequirementsCurrent
September 2017
- RFC 8247Algorithm Implementation Requirements and Usage Guidance for the Internet Key Exchange Protocol Version 2 (IKEv2)Updated
September 2017
- RFC 8268More Modular Exponentiation (MODP) Diffie-Hellman (DH) Key Exchange (KEX) Groups for Secure Shell (SSH)Current
December 2017
- RFC 8270Increase the Secure Shell Minimum Recommended Diffie-Hellman Modulus Size to 2048 BitsCurrent
December 2017
- RFC 8274Incident Object Description Exchange Format Usage GuidanceCurrent
November 2017
- RFC 8229TCP Encapsulation of IKE and IPsec PacketsObsoleted
August 2017
- RFC 8221Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)Updated
October 2017
- RFC 8308Extension Negotiation in the Secure Shell (SSH) ProtocolUpdated
March 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?