RFC 6749 · explained step by step

Understand OAuth 2.0 by watching it run.

OAuth lets an app act on your behalf without ever seeing your password. Each flow here comes with a short explanation and a simulator you can step through, request by request.

authorization_code · 1 / 5
Your appAuth serverAPI1. Ask2. Code3. Trade4. Token5. Use

The app sends the user to the auth server and says which access it wants.

GET /authorize
  ?response_type=code
  &client_id=my-app
  &redirect_uri=https://app.example/cb
  &scope=read:photos
  &state=x7Kq2

Nine flows, three purposes

A flow is one recipe for getting a token. Which one you need depends on who, or what, is asking for access.

New to this? Read them in this order

Each step assumes only the ones before it. You can stop after the first two and already know most of what you will use.

  1. 01Authorization CodeThe core idea. Everything else builds on it.
  2. 02PKCEThe same flow, hardened for apps that cannot keep a secret.
  3. 03Refresh TokenHow sessions last longer than one short-lived token.
  4. 04OpenID ConnectAdds identity, so the app knows who the user is.
  5. 05Client CredentialsThe simplest flow, for machines.
  6. 06Device AuthorizationA special case for devices with no keyboard.
  7. 07JWT BearerA stronger way for a machine to prove who it is.
  8. 08Token ExchangeHow services pass a user's access along a chain of calls.
  9. 09CIBALogin started by the app and approved on the user's phone.

Beyond the flows

OAuth in the AI eraHow OAuth is used for AI agents and MCP servers, and which RFCs and drafts to watch.