Skip to content

Spotify is removing implicit grant and insecure redirect URIs #1325

@unmanagedtn

Description

@unmanagedtn

Hi,

Got this in an email today...


In line with industry best practices, we are removing implicit grant
from our OAuth offering, as well as prohibiting insecure redirect URIs for
all clients.

These features could pose a security risk to Spotify users and partners and
we are therefore enforcing the new rules before the end of the year.

Existing applications need to migrate to an acceptable state before November 2025.

For all newly created apps, we will start automatically enforcing these rules from the beginning of April.

We have identified you as the owner of one or more apps that are using features that we are going to deprecate.
Failure to take action will cause your application to stop working as expected.

[For more details on necessary steps to take to ensure your application operates in line with these new rules, please read our blog post.

](https://wl.spotify.com/ls/click?upn=u001.No8TgQ5gmZjAOIpJLzd41D3Mz6DH7FZ905vBJfekre-2FqqaHuHe7a-2B8d3ZFfZBJXGhV6HsSr9w7mqTUgzBDbbJRXfgHoOUWcKhkvOLpfPyg24qpd6-2F2uWG6P3qt-2BrVZg4uPJV72F8GCQ19pmrM0xPCOPCV8JCp0cWDCx8lAUAjzw-3DLyG1_uFcsKQw5tjHrVEfeDdbD-2Fq4aGweHroJutZfKK7kO-2FmRxSGoq2MABtOEaNjmTUzvo5GyihADVfJ6jXQwWUXu-2BD3-2BtMs5NVEMJiH1jD6OQzvRai9e2aP1vrIUxX0ppm7EbZznRRzLhYTrEf49IE4ug-2BkSY1iFY4o4M3MUl3E5xRqztG2knv-2B-2BrHBzazdgXcAdmP6wdG-2BTPy4R8gu8LorYKjeUDRQmQzKLni-2F1JLoy68ezxokYBA4W-2B8orHpKIYdo2-2FfgWVcc6V0fA6wZXnF2fVzfygA4Oyf8blsQc5wZ-2FtzopVtlX0PemiYhW2644LEvccZ79EkY68fzDu68bt8MiWPhAubxVoyVjP7UOgZTDUJlLcWah-2FCAdTYYg7jOJ0XMDCfpwBp2-2BV9VRkU77n-2FqOO-2BJiHkUde8oz4G0SJ-2BrW0gzSbPt3swCQ-2FoAB5kIzyPZXb32WflIo03ktnnH7gVagXhEbpPqlr9XbR8SHI6-2F7rzIvriS9zx37nSiQNSxkvW-2FhipiFPl8s4dJpDysG-2F1jIUBa-2FgapbdfZuXCredXzQnRvhdF6dnkf44-2FjguyA-2Btwxp7)

Regards,

The Auth team at Spotify

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugA functionality or parts of a program that do not work as intended

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions