I'd imagine you have to pre-register each client and then use HOTP or TOTP
to generate one-time passcodes.

On Thu, 9 Apr 2020 at 08:25, Daniel Fett <f...@danielfett.de> wrote:

> Hi Francis,
> Am 08.04.20 um 23:59 schrieb Francis Pouatcha:
> As a replacement of RFC 6749 I am missing a "Direct Grant" with the same
> simplicity as the "Resource Owner Password Credentials" grant of RFC 6749..
> The reason is that browser redirects are too complex and most of the time
> badly implemented by small teams. For the sake of having SMEs use oAuth 2..1
> with their limited development capacities, I suggest keeping the simple 
> "Resource
> Owner Password Credentials" with an OTP replacing the permanent password.
> How does the Client get the OTP in that case?
> -Daniel
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth

<https://www.pingidentity.com>[image: Ping Identity]
Rob Otto
EMEA Field CTO/Solutions Architect

c: +44 (0) 777 135 6092
Connect with us: [image: Glassdoor logo]
LinkedIn logo] <https://www.linkedin.com/company/21870> [image: twitter
logo] <https://twitter.com/pingidentity> [image: facebook logo]
<https://www.facebook.com/pingidentitypage> [image: youtube logo]
<https://www.youtube.com/user/PingIdentityTV> [image: Blog logo]
*If you’re not a current customer, click here
a more relevant offer.*

_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._
OAuth mailing list

Reply via email to