Authorization Code
The Authorization Code Grant is the primary flow used within OAuth2, since it is used for web-based redirect sign in experiences.
Implementation
From the Client SDK perspective, this is implemented as a two-step flow.
- The
startfunction is used to communicate with the OAuth2 server, and generates a URL which should be opened within a browser. The browser will proceed through a series of page loads / redirections, ultimately returning to theredirect_urisupplied to the start function. This redirection will include a number of attributes on the URI query string, which will be used to continue the flow. - Once the redirect URI is received, it should be supplied to the
resumefunction, at which point the code embedded in the URI will be exchanged for a Token.