106
VIEWS
I put together a sequence diagram of the OAuth Wrap Web App Profile.
# I wish something like this were included in the spec itself…
Notes:
- The wrap_client_id and wrap_client_secret are assigned to the WebAppClient by the AuthzServer in advance.
- The Access Token is an opaque string agreed upon between the Resource and the AuthzServer, and it functions as a Bearer Token.
- Since all communication takes place over HTTPS, signatures are considered unnecessary.[*1]
Related posts

IETF 123: OAuth WG Session 2 Summary (Japan Time, the 25th)
Quite some time has passed, and my memory is already hazy... Below, I will see whether I can remember it while rewriting the summary that NotebookLM…

IETF 123: OAuth WG Session 1 Summary (Japan Time, Day 24)
Overview On July 24 Japan time, OAuth WG Session 123 at IETF 1 Madrid was held. The previously announced agenda was as follows, but a session…

Data Sustains Lives—MyDataConference 2026 Opening Address
The following is the opening address for the MyData Japan Conference 2026, delivered by Nat Sakimura in his capacity as Chair of the General Incorporated Association…
