Skip to content
Mermaid templates

Sequence — OAuth 2.0

Authorisation-code flow with PKCE and refresh.

Template previewMermaid
Rendering…

Make it your own.

sequenceDiagram
participant U as User
participant C as Client App
participant A as Auth Server
participant R as Resource API

U->>C: Click "Sign in"
C->>A: /authorize?code_challenge=…
A->>U: Login prompt
U->>A: Credentials + consent
A-->>C: redirect with auth code
C->>A: /token (code + code_verifier)
A-->>C: access_token + refresh_token
C->>R: GET /me (Bearer)
R-->>C: profile JSON
Note over C,A: 1 hour later
C->>A: /token (refresh_token)
A-->>C: new access_token