← Back to security

OAuth 2.0 Flows

6 questions · ~5 min · intermediate

Six questions on the real moving parts of OAuth 2: delegation versus identity, code plus PKCE, callback correlation, audience and scope enforcement, machine tokens, and the legacy password-based grant that should stay retired.

0 / 6

Which flow is the current best practice for browser SPAs and native apps that cannot keep a long-term client secret?

Press 1 to 4 to pick an answer