@Xavi Moll
Thank you for your time and patience! We were able to get another update on this from our engineering team and I'll post it below.
Update:
This is confirm my sign in (CMSI). If Native apps were allowed to silently pop a browser, get new tokens, and close again without the user seeing more than a flash, there's no saying what app is actually being signed into.
Mobile platforms don't secure custom URIs - For example, the Flashlight app can very easily sit on MyBank:// and request tokens as if it were your bank, taking advantage of the fact your already auth'd in the browser and consented to your bank app (which has registered MyBank:// as a redirect URI). So we cannot ever give a token back to a native app from the system browser without some user interaction where they confirm that the auth window launched by Flashlight app really matches their expectations.
As of right now our engineering team will be looking into potentially implementing this, however, there is no ETA at this time.
If you have any other questions, please let me know.
Thank you again for your time and patience throughout this whole issue.
----------
Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.