@aaronpk are you aware of any OAuth implementations using unregistered clients (RFC 6749 section 2.4) in the wild? It seems to me that requiring client registration discourages self hosting OAuth servers. For example, I'm working on a storage service where each user will 1/
1
You're not wrong.
You may want to give this a read, which addresses that exact problem: aaronparecki.com/2018/07/07/…
We use this a lot for the case you're talking about, where app developers have no relationship with the OAuth service the app is talking to.
Jan 22, 2020 · 11:18 PM UTC
1

