Thank you! There's a concept called "public clients" when the client_id and client_secret will be public (ex: SPA web apps, mobile apps), there's no added advantage in having a client_secret. Therefore, we create public clients which only has a client_id.

If you created a non-public client, you should send the "cilent_secret" as a parameter in these requests.

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

Imesha Sudasingha
Imesha Sudasingha

Written by Imesha Sudasingha

Co-Founder @HighFlyer | Ex @WSO2 | Ex @BallerinaLang | Opensource | Member @TheASF

No responses yet

Write a response