Authorization Code Grant Flow Overview

  Рет қаралды 15,817

Michael Bissell

Michael Bissell

Күн бұрын

Пікірлер: 8
@iambhanu7
@iambhanu7 Жыл бұрын
I am confused. What is the API here ? Is it part of the Identity/Authorization setup? Or is it the server counterpart of the App.
@norunners_
@norunners_ Жыл бұрын
The API is the resource server. No, it uses the authorization services to verify access tokens against scopes protecting their endpoints/resources. No, the app (client) is an untrusted party that the user (resource owner) can grant access to their data via API (resource server).
@saikrishnapuli6591
@saikrishnapuli6591 11 ай бұрын
can you confirm, token call is happening at backend or frontend via browser?
@autumnchills2317
@autumnchills2317 Жыл бұрын
I am still fairly new to OAuth so I'm still wrapping my head around the concept of oauth clients. In your diagram, would the App be considered the oauth client or would it be the API server? I'm confused because the App would be the one consuming the token and making requests to access protected resources for the user, but the API server here is the one exchanging the auth code for tokens.
@norunners_
@norunners_ Жыл бұрын
Yes, the client is sometimes called app. For example, a user (resource owner) can authorize a third party app (client) to access their data via a API server (resource service). The authorization services powers the flow by knowing the relationships (scopes) between clients and resource owners.
@dennesmagayanes127
@dennesmagayanes127 2 ай бұрын
my issue with this now is that for our automation scripts, which obviously uses service accounts they will not work because it's not an actual user/person that has access to a UI/Browser, how to go about this? Seems like it defeats our automation purpose if everything we have to execute them we have to first get the Auth Code via browser.
@roy_c
@roy_c 28 күн бұрын
You should use client credentials Flow
@KawsarAli-s2r
@KawsarAli-s2r Жыл бұрын
tuuutft
Client Credentials Grant Flow is REALLY BAD
2:16
Michael Bissell
Рет қаралды 4,1 М.
OAuth Grant Types
6:37
Oracle Learning
Рет қаралды 78 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН
So Cute 🥰 who is better?
00:15
dednahype
Рет қаралды 19 МЛН
HashMaps & Dictionaries, Explained Simply
22:44
Nic Barker
Рет қаралды 3 М.
OAuth Authorization code flow
11:49
Jan Goebel
Рет қаралды 55 М.
OAuth Grant Types simplified for decision makers
13:16
Software Architecture and Design
Рет қаралды 12 М.
What's going on with the OAuth 2.0 Implicit flow?
17:18
OktaDev
Рет қаралды 85 М.
A Very Simple API Call
2:17
Michael Bissell
Рет қаралды 3,1 М.
OAuth Flow with PKCE
22:14
Salesforce Apex Hours
Рет қаралды 6 М.
OAuth 2.0 - Implicit grant and how it works
7:32
Sascha Preibisch
Рет қаралды 24 М.
OAuth 2.0 - PKCE
8:49
Sascha Preibisch
Рет қаралды 42 М.
OAuth 2.0 explained with examples
10:03
ByteMonk
Рет қаралды 173 М.
Why is JWT popular?
5:14
ByteByteGo
Рет қаралды 348 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН