OAuth 2.0 Authorization Code Flow
Classic three-party flow where a confidential client exchanges an authorization code for an access token.
The Authorization Code grant is the recommended flow for web applications that can keep a client secret (confidential clients). The user authenticates with the authorization server, which then issues a short-lived code that the application exchanges for tokens over a back-channel call.