OAuth client

In OAuth 2.0, the application that requests access to protected resources on the user's behalf, receiving a limited access token; RFC 6749 classes it as confidential or public.

In OAuth 2.0, the client is the application that wants to reach protected resources on behalf of the resource owner. The authorization server issues it an access token, which the resource server accepts. The client is registered with the authorization server and identified by a client identifier (RFC 6749 section 2.2). In the grants recommended today it receives a token with limited scope, not the user’s password.

RFC 6749 section 2.1 divides clients by whether they can keep a credential secret. A confidential client, such as a web application running on a protected server, can hold a client secret or another credential and authenticate itself to the authorization server. A public client, such as a mobile app or code running in a browser, cannot, because anyone with the app can extract what it contains. Public clients are the reason PKCE was introduced, so an intercepted authorization code is designed to be unusable by anyone but the client that asked for it. In OpenID Connect, the same application is called the relying party.

Exam relevance: a scenario is likely to ask which OAuth role an application plays, or how a mobile app should protect its authorization code. Candidates are expected to identify the client, and to link public clients with PKCE.