OAuth 2.0 Token Exchange and Device SSO
Innovating on Authentication Standards

Innovating on Authentication Standards

6/25/2018

What this post added

Introduced a profile of the OAuth 2.0 Token Exchange draft specification to enable mobile app identity migration without user re-authentication. Developed a new OAuth 2.0 scope (_device_sso_) to facilitate device-specific secrets, enabling a back-channel SSO solution for mobile applications signed by the same vendor, leveraging device keychain/account manager for storing id_tokens.

Read the original post ↗