OAuth 2.0 Authorization Code Flow
The standard browser-based OAuth 2.0 authorization-code exchange.
Rendering…
Make it your own.
sequenceDiagram
autonumber
actor U as User
participant B as Browser
participant C as Client App
participant A as Auth Server
participant R as Resource API
U->>B: Click "Sign in"
B->>C: GET /login
C->>B: Redirect to /authorize
B->>A: GET /authorize (client_id, scope)
A->>U: Show consent screen
U->>A: Approve
A->>B: Redirect with auth code
B->>C: GET /callback?code=...
C->>A: POST /token (code, secret)
A->>C: access_token + refresh_token
C->>R: GET /data (Bearer token)
R->>C: 200 Protected resource