Skip to main content

Authorization Code

The Authorization Code Grant is the primary flow used within OAuth2, since it is used for web-based redirect sign in experiences.

Implementation​

From the Client SDK perspective, this is implemented as a two-step flow.

  1. The start function is used to communicate with the OAuth2 server, and generates a URL which should be opened within a browser. The browser will proceed through a series of page loads / redirections, ultimately returning to the redirect_uri supplied to the start function. This redirection will include a number of attributes on the URI query string, which will be used to continue the flow.
  2. Once the redirect URI is received, it should be supplied to the resume function, at which point the code embedded in the URI will be exchanged for a Token.