Is there anything wrong with manually providing people access tokens and refresh tokens so they don't have to do the OAuth2 dance themselves?How should I ethically approach user password storage for later plaintext retrieval?Why Does OAuth v2 Have Both Access and Refresh Tokens?What is the purpose of the implicit grant authorization type in OAuth 2?Why is there an “Authorization Code” flow in OAuth2 when “Implicit” flow works so well?What is the difference between the OAuth Authorization Code and Implicit workflows? When to use each one?How should I store and revoke OAuth2 authorizations and/or refresh tokens?OAuth2 - unnecessary complexity with refresh tokenClient secret + refreshing the access token in spring oauth2OAuth2 refresh token utilityOAuth2 purpose of refresh token with authorization code

Group riding etiquette

Heat output from a 200W electric radiator?

Are there any to-scale diagrams of the TRAPPIST-1 system?

Find most "academic" implementation of doubly linked list

Normalized Malbolge to Malbolge translator

Looking for a plural noun related to ‘fulcrum’ or ‘pivot’ that denotes multiple things as crucial to success

Adding and Multiplying Elements of a list together

If I said I had $100 when asked, but I actually had $200, would I be lying by omission?

Notice period 60 days but I need to join in 45 days

Is there an in-universe explanation given to the senior Imperial Navy Officers as to why Darth Vader serves Emperor Palpatine?

Why doesn't Starship have four landing legs?

Why is 3/4 a simple meter while 6/8 is a compound meter?

Defending Castle from Zombies

Why does a sticker slowly peel off, but if it is pulled quickly it tears?

Why does Sauron not permit his followers to use his name?

Number of Fingers for a Math Oriented Race

Is it unusual for a math department not to have a mail/web server?

web scraping images

What will be the immediate action by the pilot and ATC if any plane blocks the runway while landing?

Why does AM radio react to IR remote?

How to handle inventory and story of a player leaving

Why didn't Doc believe Marty was from the future?

Can I lend a small amount of my own money to a bank at the federal funds rate?

How could a self contained organic body propel itself in space



Is there anything wrong with manually providing people access tokens and refresh tokens so they don't have to do the OAuth2 dance themselves?


How should I ethically approach user password storage for later plaintext retrieval?Why Does OAuth v2 Have Both Access and Refresh Tokens?What is the purpose of the implicit grant authorization type in OAuth 2?Why is there an “Authorization Code” flow in OAuth2 when “Implicit” flow works so well?What is the difference between the OAuth Authorization Code and Implicit workflows? When to use each one?How should I store and revoke OAuth2 authorizations and/or refresh tokens?OAuth2 - unnecessary complexity with refresh tokenClient secret + refreshing the access token in spring oauth2OAuth2 refresh token utilityOAuth2 purpose of refresh token with authorization code






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








0















This seems like an odd question, but something I've been pondering.



I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










share|improve this question






























    0















    This seems like an odd question, but something I've been pondering.



    I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



    Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



    Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



    For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



    Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










    share|improve this question


























      0












      0








      0








      This seems like an odd question, but something I've been pondering.



      I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



      Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



      Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



      For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



      Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










      share|improve this question














      This seems like an odd question, but something I've been pondering.



      I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



      Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



      Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



      For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



      Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.







      security oauth-2.0






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 27 at 21:22









      John DeverallJohn Deverall

      1,92217 silver badges26 bronze badges




      1,92217 silver badges26 bronze badges

























          0






          active

          oldest

          votes










          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55386654%2fis-there-anything-wrong-with-manually-providing-people-access-tokens-and-refresh%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes




          Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.







          Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.



















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55386654%2fis-there-anything-wrong-with-manually-providing-people-access-tokens-and-refresh%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Obelisk of Theodosius Contents History Description Notes Bibliography Further reading External links Navigation menuAge of spirituality : late antique and early Christian art, third to seventh centuryOver 60 picturesObelisks of the World41°00′21.24″N 28°58′31.43″E / 41.0059000°N 28.9753972°E / 41.0059000; 28.97539727724550-7235741376235741376

          밀양 대씨 역사 각주 함께 보기 둘러보기 메뉴밀양 대씨

          1973년 목차 사건 문화 탄생 사망 노벨상 달력 둘러보기 메뉴