ParentFull threadanderspitman·I think it mostly just evolved that way. OAuth started on the web and if you're using a browser anyway you might as well take advantage of HTML/JS rendering for the UI and cookies for secure storage.View on HN