Isn't this just reinventing OAuth?
OAuth already has grant_type and "scope" to cover different devices, flows and permissions.
OAuth already has grant_type and "scope" to cover different devices, flows and permissions.
This is a very common question we get. OAuth is great for when the permissions can be modelled as a set of roles/scopes which apply uniformity. Where that breaks down as described in the article is when there needs to be more context involved in the authoriZation - beyond simple roles from your chosen autheNtication provider.