In Oauth2.0, can a human user act as a client?

Viewed 18

As per documentation, https://www.oauth.com/oauth2-servers/definitions/

In oauth 2.0 a client is an application which wants to get access to user protected resource. I want to know, if another user can act as a client or not.

I want to integrate SSO with our REST API's implemented with python, and the consumer of our REST API's can be different applications as well as human users. Can I use Oauth 2.0 for supporting the SSO for both the types of consumer?

Note: I can not use SAML for SSO (because our REST API doesn't support SAML)

1 Answers

In short - no, a client is an application.

You are mixing some terms here, though. You say "the consumer of our API can be human users". As of 2021 we humans still can't consume REST APIs directly, unfortunately, we need a computer for that ;) And seriously — human users will always use some kind of application to consume your API. It might be curl, httpie, a browser, some simple SPA, an advanced website, or a mobile app. All of these are OAuth clients — the concrete applications that actually make the HTTP request to your API. It doesn't matter that in the end they are operated by a human, these are still OAuth clients. And in this sense, you will always have an OAuth client that is an application, and that communicates with your API.

Related