Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3851930
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 19, 20262026-05-19T17:14:19+00:00 2026-05-19T17:14:19+00:00

I am implementing an OAuth 2 provider and am wondering if it’s necessary to

  • 0

I am implementing an OAuth 2 provider and am wondering if it’s necessary to generate both an API key and a client id for clients when they register an app with my provider.

From looking at OAuth 1.0a providers like Google and Twitter, they only have one key for clients, but Facebook (OAuth 2) has both an API key and an application id, but uses the app id as their “client_id” param in their OAuth 2 dance.

I’m pretty sure neither the OAuth 1.0a nor OAuth 2 spec specifies more than one key for the client.

I am not sure in what context a provider would need to generate both for a client app.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-19T17:14:20+00:00Added an answer on May 19, 2026 at 5:14 pm

    I bet that Google and Twitter also uses application IDs in their database record for each application. In twitter, when you manage your OAuth apps you go to http://dev.twitter.com/apps/1234 where 1234 is the application ID.

    It’s just that in Facebook, they started using “apps” before OAuth and they have been using the application ID for apps to identify itself in requests since the start. It probably is just a some decision their developers made to lessen the complexity on their end.

    In conclusion the application id is just their way of keeping track of applications, so the question is how will you?

    Just note that when an application is compromised there should be an option to reset the consumer key and/or secret.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm implementing the provider side of a two-legged OAuth protocol for API authentication. We
I'm implementing an oauth provider using DotNetOpenAuth CTP library. So I have created an
I'm looking at implementing an app getting Twitter authorization via Oauth in Java. The
I have a Rails app acting as an OAuth 2.0 provider (using the oauth2-provider
I am implementing an OAuth Provider using DevDefined library. I wonder if there is
I'm implementing OAuth in my app using gtm-oauth or oauthconsumer (haven't decided yet which
Are there any recommended resources for implementing a custom membership provider that uses oAuth?
I'm implementing a strategy to connect to an OAuth provider implemented using oauth-plugin. In
I am implementing an OAuth Provider to secure different web-based APIs. The most headache
I'm implementing C2DM for my Android app. Client side (Android) went well, but I'm

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.