This article examines why the Browser-Based OAuth Client (BBOC) pattern represents the least secure OAuth architecture, identifying the risks it introduces and when it may still be acceptable. The authors provide guidance on safe implementation strategies and migration paths away from BBOC for teams that are currently using it. The piece is part of FusionAuth’s broader series on OAuth security best practices.