Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Why use the authorization code flow?

Imagine you are building a printing application. A user wants to print photos stored with another service, so your application needs permission to retrieve those photos on their behalf. It should not need their photo account password or unrestricted access to their account.

This is delegated access. The authorization code flow lets your application send the user to the photo service, where they can sign in and authorize access. Your application then exchanges the returned code for an access token and uses it to request the photos it is allowed to read.

Use this flow when an application needs access on behalf of a user and can direct their browser to the authorization service as part of establishing that access.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 1 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 1A printing app needs to retrieve a user's photos from another service. Why use the authorization code flow?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity