How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Browser-Based OAuth Client: The architecture you shouldn't be using

calendar_today June 3, 2026 person Nathan Contino, Kim Maida domain fusionauth

This article examines why the Browser-Based OAuth Client (BBOC) pattern represents the least secure OAuth architecture, identifying the risks it introduces and when it may still be acceptable. The authors provide guidance on safe implementation strategies and migration paths away from BBOC for teams that are currently using it. The piece is part of FusionAuth’s broader series on OAuth security best practices.

open_in_new Read original post