OpenID Connect - Implicit Flow

Legacy browser-based flow where tokens are returned directly in the redirect URI fragment. Deprecated in favour of Authorization Code + PKCE.

User Login & SSO

The Implicit flow was designed for public Single-Page Applications without a back-end, before PKCE existed. It returns the ID token (and optionally an access token) directly in the fragment of the redirect URI.

While modern guidance recommends Authorization Code with PKCE, when used with Form Post response mode, Implicit Flow offers a simplified workflow if the application only needs an ID token to authenticate the user.

OpenID ProviderClient AppBrowserUser/BrowserOpenID ProviderClient AppBrowserUser/BrowserClick "Login"1GET /login2302 to IdP3GET /authorize4Login5Credentials6Consent prompt7Scope approval8Form POST response9POST to redirect_uri10Validate ID token11Set authenticated session12Access welcome page13200 OK - Welcome page14

Official Specifications

Additional Resources

Back to all diagrams