freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #36 of 45

oauth · authorization code flow

RestaVSThe 401 Bandit
Resta saysThe Authorization Code flow is OAuth’s secure path for apps with a backend.

The standard flow: redirect the user to the provider, who sends back a short-lived authorization code; the app's server exchanges that code (plus its secret) for tokens. The code-in-browser, secret-on-server split keeps tokens off the client. Add PKCE for public clients (SPAs, mobile) that can't keep a secret.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleOrder the steps: redirect, consent, code, token exchange.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>1 redirect user → provider
2 user consents
3 provider → app?code=abc (browser)
4 app server: code + secret → tokens</pre></body></html>
▶ Open the interactive comic issue
‹ Oauth 2.0 · Delegated AccessOauth · Client Credentials · Device Code ›