We have a number of clients that use our API to power their websites.
I have started a conversation at work about using OAuth to make authenticated API Calls. We wi
about 1) Saving the access token and secret in a cookie
consider your client in an internet cafe and what happens after he doesnt clear cookies and next person copies this informations?
I'd go for DB or PHP session