Will Adams

Surely the vulnerability here is that you have a site vulnerable to XSS not the choice of where to store the token?

Putri Karunia

Hi Will, Putri here – Michelle' cofounder.

Yes, technically if your site is vulnerable to XSS, the attacker can do a lot of damage no matter where you store the token. The options above are intended to help in making it harder for the attacker to obtain the access token itself.