# OAuth: distinguish clients before designing the flow

https://thiago.limaesilvatecnologia.com.br/en/artigos/oauth-client-boundaries/

Published: 2026-09-12

Mobile apps, browsers and backends have different boundaries.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: June 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

Copying one authentication design across clients can hide storage and execution differences. Explain where credentials exist and who can access them.

## Practical application

Editorial proposal: model browser, application and backend separately. In a hypothetical scenario, record redirects, token purposes and server responsibilities. Confirm the appropriate flow in provider documentation.

## How to verify

Test cancellation, repetition and unexpected returns. Preserve the relationship between request and response. Deliver a justified contract per client type instead of a universal configuration that is difficult to defend.

## Sources

- [OWASP — OAuth2 Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/OAuth2_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
