Why does Oauth2.0 says, "Client Password in request body not recommended"?

Viewed 171

Client authentication of oauth spec indicates the following in section 2.3.1:

   Including the client credentials in the request-body using the two
   parameters is NOT RECOMMENDED and SHOULD be limited to clients unable
   to directly utilize the HTTP Basic authentication scheme (or other
   password-based HTTP authentication schemes).

I don't understand the reason why this is not recommended. How is Http Basic Auth better than this approach? Can some one explain?

1 Answers
Related