Resta saysThe Authorization Code flow is OAuth’s secure path for apps with a backend.
The standard flow: redirect the user to the provider, who sends back a short-lived authorization code; the app's server exchanges that code (plus its secret) for tokens. The code-in-browser, secret-on-server split keeps tokens off the client. Add PKCE for public clients (SPAs, mobile) that can't keep a secret.
Power-ups you unlock
Redirect → code → server exchanges for tokens
Keeps tokens off the browser
Server holds the client secret
PKCE secures public clients
The 401 Bandit attacks — common mistakes
Exchanging the code in client-side JS
Skipping PKCE for SPAs/mobile
Not validating the state parameter (CSRF)
Boss battleOrder the steps: redirect, consent, code, token exchange.