OAuth Flow Simulator
Follow OAuth requests, codes, and tokens as they move between people, apps, auth servers, and APIs.
Recommended
Authorization Code with PKCE
The browser carries a short-lived code, while a one-time PKCE verifier binds token issuance to the client that started the flow.
Sequence traceEach row is one message
Click a row to inspect its codeMessage / step
PersonResource owner
BrowserBrowser / user agent
ClientClient application
Auth serverAuthorization server
APIProtected API
Step 1 · Prepare
ClientClientCreate transaction-bound values
Complete code sampleFictional wire view
code_challenge = S256(verifier) state = tx_8f21 nonce = oidc_b71a
Receiver actionCreate transaction-bound values
The app creates one-time values before opening the sign-in page.
Protocol detail and checks
Generate a high-entropy code_verifier, derive code_challenge=S256(verifier), and create state. OIDC clients also create nonce.
Use a fresh verifier for every attemptStore state only for the current transaction
End state
The client receives an access token without placing that token in the authorization redirect.
Educational model, not a security verdict
Messages are fictional and simplified. A completed trace does not verify a deployment, token, signature, certificate, session, trust relationship, or authorization policy.