Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Roles and endpoints

The participants

Giving another application limited access named the four OAuth roles in the photo book example. Following the connection in detail means being precise about which decisions belong to each of them.

RoleWhat it decides in our example
Resource ownerYou decide whether the printing application may read your photos.
ClientThe printing application decides what access to ask for, then uses the token it receives.
Authorization serverThe photo service's authorization system handles your sign-in and approval and decides which tokens to issue.
Resource serverThe photo API decides whether each request, with its token, may retrieve the photos it asks for.

These are roles, rather than a requirement for four separate machines or companies. The photo service might operate both the authorization server and the resource server. A company might instead use a separate identity platform as its authorization server.

The word client can also be misleading at first. Here, it means the application seeking access. The printing application's backend can be an OAuth client even though it is itself a server handling requests from browsers.

The endpoints

These participants communicate through endpoints: addresses that receive requests for a particular purpose.

In the authorization code flow, three addresses are especially useful to recognize:

AddressWhat happens there
Authorization endpointThe client directs your browser here to begin an authorization interaction.
Redirect URIThe address at the client where your browser returns with the authorization response.
Token endpointThe client sends a request here to exchange an authorization code for tokens.

For our fictional services, those addresses might look like this:

Authorization endpoint:
https://auth.photos.example/authorize

Client redirect URI:
https://printer.example/oauth/callback

Token endpoint:
https://auth.photos.example/token

These addresses are illustrative. They do not send requests, and the path names are not required OAuth spellings. The responsibilities of the endpoints are what matter.

Three addresses in a backend client's authorization code flow: the browser begins authorization at the authorization server, returns with the response to the client's redirect URI, and the client backend exchanges the code for an access token at the authorization server's token endpoint.
The authorization and token endpoints belong to the authorization server. The redirect URI belongs to the client. View full-size illustration (opens in a new tab)

Following the messages

The authorization code is an intermediate credential. The client receives it through the browser's return journey, then presents it at the token endpoint. It is not the access token used to retrieve your photos.

After obtaining an access token, the client calls the photo API. The API checks whether the token and the requested operation are acceptable before returning any photos.

Your browser carries some of these messages, but it is not an additional OAuth role. In this example, it helps you interact with the authorization server and carries the authorization response back to the client. Other exchanges happen through direct requests from the client.

This outline describes the authorization code flow. Other grants use different exchanges, and some do not involve a browser or an interactive user at all.

Starting with Why use the authorization code flow?, the authorization code flow lessons follow the full sequence with request URLs, HTTP messages, and the checks required at each step.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 1 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 1The printer receives an authorization code at its redirect URI. What happens next in the authorization code flow?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity