OAuth 2.0 for Browser-Based Apps
This document describes security requirements and best practices for OAuth 2.0 in SPAs and other browser-based apps — applications where all code runs in the browser and there is no secure backend to hold secrets.
When to use this
Follow this guidance when building any application that runs entirely in a web browser — React, Vue, Angular, or plain JavaScript SPAs. The key recommendations: always use Authorization Code + PKCE, never use the Implicit flow, and consider a Backend-for-Frontend (BFF) pattern to keep tokens out of the browser entirely.
Browser-based apps are public clients — they cannot store a client secret. Code, tokens, and storage are all visible to any JavaScript running on the page, including third-party scripts. The recommended approach is Authorization Code + PKCE with tokens stored in memory only (not localStorage), or better: a BFF that holds tokens server-side and communicates with the browser via HttpOnly cookies.
More resources
- Single-Page Apps (oauth.com)
- Single-Page Apps (aaronparecki.com)
- Why you should stop using the OAuth implicit grant (Torsten Lodderstedt)