I am implementing an OAuth2 provider, and I would like to have an area somewhere on my website where developers register and register third-party applications. But I have doubts about how to generate the application client identifier and client secret. Should they be unique random codes or should they have some meaningful information for the client? I think they may be random.
Well, I was looking for best practices on how to do this, but never found. Therefore, any answers will be appreciated.
PD: Im developing on .NET MVC3 with a library called DotNetOpenAuth.
Daniel
source share