OAuth Security Assessment Form
Assess the security posture of your OAuth implementation, including grant types, redirect URI validation, PKCE, client secret handling, token storage, and remediation notes.
OAuth Implementation Context
Application Name
*
Deployment Environment
*
Development
Staging
Production
Multi-environment
OAuth Grant Type(s) Used
*
Authorization Code
Authorization Code with PKCE
Client Credentials
Device Code
Implicit
Refresh Token
Other
OAuth Provider(s) Used
Security Controls Assessment
Redirect URI validation status
*
Strict exact-match validation
Partial validation
Wildcard or loose matching
Not implemented
Unsure
PKCE usage
*
Always
Sometimes
Not used
Not sure
Client secret handling
*
Securely stored and access-controlled
Stored in source control or configuration files
Shared credentials used across multiple apps
No client secret used
Unsure
Token storage approach
*
Browser storage
Server-side storage
Mobile secure storage
Mixed approach
Unsure
Token lifetime and revocation practices
*
Access tokens are short-lived and refresh tokens are rotated with revocation support
Some practices are in place, but not consistently
Revocation is not supported
Practices are unclear
Unsure
Risk Review and Notes
Scope minimization review
*
Minimal
1
2
3
Excessive
4
1 is Minimal, 4 is Excessive
Current security concerns or incidents
Submit OAuth Security Assessment Form
Should be Empty: