L23 · OAUTH 2.0
Run the code flow by hand
Register a client, build the authorization request, exchange the code with curl and call UserInfo.
Planned
Steps
Read your test tenant's discovery document and find each endpoint.
What the server will check: Nothing to check. Note the authorization, token and UserInfo endpoints.
Register a client whose redirect URI is the lab callback page.
What the server will check: The client exists in your tenant.
Build the authorization URL, open it and sign in as a test user.
What the server will check: Your tenant returned a code to the callback page.
Exchange the code for tokens with curl.
What the server will check: A successful token exchange for your client.
Try the same code a second time.
What the server will check: The second exchange was rejected.
A code works once. A second attempt suggests it was intercepted.
Call UserInfo with the access token.
What the server will check: A UserInfo request with that token.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
- The lab callback page
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.