OAuth Flow Simulator

OAuth Flow Simulator

Follow OAuth requests, codes, and tokens as they move between people, apps, auth servers, and APIs.

Interactive protocol lesson

Four original grants; no fixed total after extensions.

Follow the message row, then inspect the code received by the next actor.

7 scenarios
Recommended

Authorization Code with PKCE

The browser carries a short-lived code, while a one-time PKCE verifier binds token issuance to the client that started the flow.

Step 1 of 7Show the risk and defensive control for the selected protocol message.
Sequence traceEach row is one message
Click a row to inspect its code
Message / step
PersonResource owner
BrowserBrowser / user agent
ClientClient application
Auth serverAuthorization server
APIProtected API
Step 1 · Prepare

Create transaction-bound values

ClientClient
Complete code sampleFictional wire view
code_challenge = S256(verifier)
state = tx_8f21
nonce = oidc_b71a
Receiver actionCreate transaction-bound values

The app creates one-time values before opening the sign-in page.

Protocol detail and checks

Generate a high-entropy code_verifier, derive code_challenge=S256(verifier), and create state. OIDC clients also create nonce.

Use a fresh verifier for every attemptStore state only for the current transaction
End state

The client receives an access token without placing that token in the authorization redirect.

Educational model, not a security verdict

Messages are fictional and simplified. A completed trace does not verify a deployment, token, signature, certificate, session, trust relationship, or authorization policy.