OAuth 2.1 and OpenID Connect Flows
What OAuth is (delegated authorisation) and is not, the authorisation code flow with PKCE, client credentials for machines, the device flow, refresh tokens and rotation, scopes and consent, OpenID Connect ID tokens and discovery, and the flows OAuth 2.1 removed.
The code flow with PKCE
OAuth lets a client act on a user's behalf with limited permission (scopes) without the user's password. OpenID Connect adds authentication on top: an ID token that says who the user is, a userinfo endpoint and discovery (/.well-known/openid-configuration).
Other flows, refresh tokens and what 2.1 removed
| flow | use |
|---|---|
| authorisation code + PKCE | every user-facing app: web, mobile, SPA (via a BFF ideally) |
| client credentials | a service acting as itself (no user): batch jobs, service-to-service |
| device authorisation | TVs, CLIs: show a code, user approves on their phone |
| refresh token | renew access tokens; rotate on every use and detect reuse (reuse = theft: revoke the family) |
| token exchange (RFC 8693) | a service swaps a user token for a narrower one to call downstream |
| removed in 2.1: implicit, password grant | tokens in URLs and apps handling passwords were the problem |
ID token versus access token: the ID token is for the client (who logged in); the access token is for the API (what may be done). Never send ID tokens to APIs as access tokens, and never use access tokens to establish the user's identity in the client.