L25 · OAUTH 2.0
Two kinds of client
Register a public and a confidential client, and see the token endpoint refuse a confidential client without its secret.
Planned
Steps
Register a public client and exchange a code using PKCE.
What the server will check: A successful exchange for the public client.
Register a confidential client and try to exchange a code without its secret.
What the server will check: The token endpoint rejected the client.
Try again with the secret.
What the server will check: A successful exchange for the confidential client.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
- The lab callback page
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.