Dear readers,
I know what is a Client ID and Client Secret. What i miss is how client secret can add security to client id. I.e. with respect to the case if i would only have the client id (api key). In the password owner or client credential flows i would store both secretly - so why wouldn't client id alone suffice? if one can steal client id can also likely steal client secret as well. I read that client id is considered public..mmhh is that really true? If so, in what sense client secret is considered private?
Pls help to fix our issues.
thanks lot.