Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

L25 · OAUTH 2.0

Two kinds of client

Register a public and a confidential client, and see the token endpoint refuse a confidential client without its secret.

Planned

Steps

  1. Register a public client and exchange a code using PKCE.

    What the server will check: A successful exchange for the public client.

  2. Register a confidential client and try to exchange a code without its secret.

    What the server will check: The token endpoint rejected the client.

  3. Try again with the secret.

    What the server will check: A successful exchange for the confidential client.

When it opens

This lab is planned. It opens when these are in place:

  • Lab setup and cleanup in your test tenant
  • The lab callback page

The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.

Learn the theory

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab