I am trying out the OAuth2 authentication for building a CLI for various build and test automation.
When creating the oauth consumer I came across the "This is a private consumer " checkbox
The help text states:
"Installable applications that ship their OAuth consumer credentials as part of the application should not be marked as private."
I am using the Authorization Code Grant flow and would be distributing the oauth client secret with the CLI tool internally in our company, so I guess I should leave the "private consumer" checkbox unchecked.
But I can't figure out what difference the private flag actually makes?
If the secret and a refresh token was leaked from a device, it seems I can still use these to get an access token.
Best regards
Rasmus