SAML Single Sign-On (SSO) Integration
Improving OAuth ROPC security on GitLab.com

Improving OAuth ROPC security on GitLab.com

4/1/2025 · GitLab Security Team

What this post added

This post details the upcoming requirement for client authentication in OAuth ROPC on GitLab.com, effective April 8, 2025. It explains that existing ROPC integrations without client credentials will face service disruption and provides instructions on how to register applications to obtain client credentials (client_id and client_secret) and update authentication requests accordingly. The post highlights the security benefits of client authentication, including enhanced security, standards compliance, and improved auditing.

Read the original post ↗