advancedSpring Security
Explain the OAuth2 Authorization Code Flow. When is it used?
The user is redirected to the Authorization Server to authenticate and consent; it redirects back with a short-lived code; your backend exchanges that code (server-to-server, with a client secret that's never exposed to the browser) for an access + refresh token, then uses the access token to call the Resource Server. Used for server-side web apps — the most secure flow when you have a confidential backend.
This is a Pro question
Sign in, then upgrade to Pro or Power to unlock this question and the full Interview Prep bank.
Explain the OAuth2 Authorization Code Flow. When is it used?