Skip to main content

OAuth2 Capabilities

One of the core capabilities within the Client SDK is support and adherence to the IETF OAuth2 Specifications and their workflows. The specs describe how to implement these flows and behaviors from a lower-level HTTP request basis, but there is no guidance on patterns for adopting these features consistently, or with a developer experience point-of-view.

The features in this section describe the common patterns and interfaces used to simplify the use of these OAuth2 features as much as possible.

The primary SDK Development Philosophy still applies, but the OAuth2 features expand upon this to simplify the developer experience both for users of the SDK, and maintainers supporting its development.

  1. Encapsulated Business Logic – Wherever possible, the implementation details for how an OAuth2 workflow functions should be encapsulated. Users of the SDK should not need to be experts in authentication to integrate it into their applications.
  2. Strict Adherence to Open Standards – All required features of an OAuth2 specification should be supported. When it comes to a security recommendation, all optional features should also be implemented.
  3. Customization and Extension – The OAuth2 standards are meant to be extended by implementors, with support for additional query options, claim values, additional flows, etc. As a result, any object or payload should assume that additional parameters may be included, and should make affordances to allow them to be accessed.