Intelligence

RFC 10017 OAuth 2.0 for Browser Based Applications

Moving tokens to a backend changes exposure but leaves the application responsible for requests made through an authenticated browser. The specification is a security baseline; it does not independently resolve the legitimacy of an agent action performed within an existing session.

What does this source establish about the mechanism and its authority boundary?

Moving tokens to a backend changes exposure but leaves the application responsible for requests made through an authenticated browser. The specification is a security baseline; it does not independently resolve the legitimacy of an agent action performed within an existing session.

What the source establishes

RFC 10017, published as an IETF Best Current Practice in August 2026, compares browser OAuth architectures, including a backend for frontend and browser clients. It evaluates malicious JavaScript, token theft, browser request proxying and storage choices, while recommending the authorization code flow with PKCE.

Moona assessment and evidence limits

Moving tokens to a backend changes exposure but leaves the application responsible for requests made through an authenticated browser. The specification is a security baseline; it does not independently resolve the legitimacy of an agent action performed within an existing session.

Verification scope

Moona reviewed the retained source on 29 September 2026. Source acquisition and review establish provenance for this account; they do not reproduce an experiment, validate a vendor deployment or authorize an action.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

Related Intelligence

All Intelligence Records →