# Replacing the OAuth service

**URL:** https://forum.duplicati.com/t/replacing-the-oauth-service/17447
**Category:** Developer
**Created:** [February 23, 2024, 12:10pm UTC](https://forum.duplicati.com/t/replacing-the-oauth-service/17447 "2024-02-23T12:10:45Z")
**Posts on this page:** 1
**Showing post:** 11

<div class="post-metadata">

### Author: ![ts678](https://forum.duplicati.com/letter_avatar_proxy/v4/letter/t/8491ac/32.png) [@ts678](https://forum.duplicati.com/u/ts678)
#### Post date: [February 23, 2024, 5:37pm UTC](https://forum.duplicati.com/t/replacing-the-oauth-service/17447/11 "2024-02-23T17:37:49Z")

</div>

> [@kenkendk](#):
>
> If that secret is present with the client

[Rclone OAuth Implemented Incorrectly. Exposes Client Secrets?](https://forum.rclone.org/t/rclone-oauth-implemented-incorrectly-exposes-client-secrets/19257/9) explains why they went the other way. Either way has issues, and I’m not sure which is worse. Secrets in source got rclone [banned from ACD](https://forum.rclone.org/t/rclone-has-been-banned-from-amazon-drive/2314), however that’s just an illustration of the who-holds-the-secrets issue, because [they’re discontinued now](https://forum.duplicati.com/t/amazon-cloud-drive-discontinued/7391).

> [@kenkendk](#):
>
> not something I think regular users can be expected to do.

However corporate IT departments might prefer to set up their private C# server, just the way they like.

As a side note, there can reportedly be performance advantages to cutting loose from the large crowd.  
[Making your own client\_id](https://rclone.org/drive/#making-your-own-client-id) talks about how things like rate limiting can be tied to specific client ID used.

Detailed directions there are interesting. Seemingly Google doesn’t mind taking a program’s app name repeatedly, but if someone abuses them, I wonder if it’s their client ID or our app that gets into trouble?

> [@kenkendk](#):
>
> any abuse will cause all users of the same secret to be cut off.

sounds like a vote for not sharing our secret, but I don’t know if our app gets dragged in by association.

EDIT:

Actually, the end user could also get dragged in. Is there any reliable data on who/what gets a ban first?

---

_[View the full topic](https://forum.duplicati.com/t/replacing-the-oauth-service/17447)._
