OAuth 2.0 Authorization Code Flow

Classic three-party flow where a confidential client exchanges an authorization code for an access token.

Application & API Security

The Authorization Code grant is the recommended flow for web applications that can keep a client secret (confidential clients). The user authenticates with the authorization server, which then issues a short-lived code that the application exchanges for tokens over a back-channel call.

OPResource ServerAuthorization ServerClient AppBrowserUserOPResource ServerAuthorization ServerClient AppBrowserUserOpen protected page1GET /page2GET api/resource3401 Unauthorized4302 to /authorize5GET /authorize6Login7Credentials8Consent prompt9Scope approval10302 to redirect_uri11GET redirect_uri12POST /oauth/token13Access_token14GET /api/resource15200 OK - Resource payload16Rendered page17

Official Specifications

Additional Resources

Back to all diagrams