freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #37 of 45

oauth · client credentials · device code

RestaVSThe 401 Bandit
Resta saysClient Credentials and Device Code flows cover machine and input-limited clients.

Not every flow involves a user. The Client Credentials flow authenticates a machine/service directly (its own id + secret → token) for server-to-server APIs. The Device Code flow handles TVs and CLIs with no browser/keyboard: the device shows a code, you approve it on your phone. Pick the flow that matches the client's capabilities.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleMatch each flow to: a cron job, a smart TV, a web app with login.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>cron job   → Client Credentials
smart TV   → Device Code
web app    → Authorization Code (+PKCE)</pre></body></html>
▶ Open the interactive comic issue
‹ Oauth · Authorization Code FlowOpenid Connect · Oauth + Identity ›