{
  "draft": "draft-ietf-oauth-browser-based-apps-27",
  "doc_id": "RFC10017",
  "title": "OAuth 2.0 for Browser-Based Applications",
  "authors": [
    "A. Parecki",
    "P. De Ryck",
    "D. Waite"
  ],
  "format": [
    "XML",
    "TEXT",
    "HTML",
    "PDF"
  ],
  "page_count": "49",
  "pub_status": "BEST CURRENT PRACTICE",
  "status": "BEST CURRENT PRACTICE",
  "source": "Web Authorization Protocol",
  "abstract": "This specification details the threats, attack consequences, security considerations, and best practices that must be taken into account when developing browser-based applications that use OAuth 2.0.",
  "pub_date": "August 2026",
  "keywords": [
    "JavaScript",
    "JS",
    "Single-Page App",
    "SPA"
  ],
  "obsoletes": [],
  "obsoleted_by": [],
  "updates": [],
  "updated_by": [],
  "see_also": [],
  "doi": "10.17487/RFC10017",
  "errata_url": null
}