147
VIEWS
I put together a sequence diagram of the OAuth Wrap Web App Profile.
# I wish something like this were included in the spec itself…
Notes:
- The wrap_client_id and wrap_client_secret are assigned to the WebAppClient by the AuthzServer in advance.
- The Access Token is an opaque string agreed upon between the Resource and the AuthzServer, and it functions as a Bearer Token.
- Since all communication takes place over HTTPS, signatures are considered unnecessary.[*1]
Related posts

IETF 123: OAuth WG Session 2 Summary (Japan Time, the 25th)
Quite some time has passed, and my memory is already hazy... Below, I will see whether I can remember it while rewriting the summary that NotebookLM…

OpenAI Launches Sign in with ChatGPT (Based on OpenID Connect)
(Work in progress; last updated 2026-10-02 12:39 JST) On September 29, at DevDay 2026, OpenAI officially announced Sign in with ChatGPT (SIWC). I would like to…

When Software Becomes Staff: Governance, Security, and Safety for Agentic AI
Below is the transcript of my keynote speech at EIC 2026 on May 19, 2026. The slides are provided as a PDF at the end of…
