Why use the authorization code flow?
Imagine you are building a printing application. A user wants to print photos stored with another service, so your application needs permission to retrieve those photos on their behalf. It should not need their photo account password or unrestricted access to their account.
This is delegated access. The authorization code flow lets your application send the user to the photo service, where they can sign in and authorize access. Your application then exchanges the returned code for an access token and uses it to request the photos it is allowed to read.
Use this flow when an application needs access on behalf of a user and can direct their browser to the authorization service as part of establishing that access.