✨
AppSec & Pentest
Ctrlk
  • AppSec Book
  • Intro
  • PII: Персональные данные
  • Поисковые движки
  • Построение модели угроз / анализ угроз
  • Платформы оркестрации, автоматизации пентеста
  • Audit and Compliance
  • Methodologies
  • peoples & blogs
  • Базы уязвимостей
  • Pentest IDE
  • Payloads & Wordlists
    • Генерация wordlists
    • Payloads
    • Расширения файлов, которые можно искать
    • Bypass Something
  • AppSec / WEB
    • Common
    • Automated WebApp Pentest
    • Server-Side Vulnerabilities
    • Client-Side Vulnerabilities
    • Technics
    • SSDLC
    • DevSecOps
    • Browser PWN
    • Вопросы
    • ЯП
    • Books & Papers
    • Tools
  • Technologies
    • WEB
      • Аналитика & Маркетинг
      • RSS-каналы
      • CMIS
      • HTTP/WEB
      • CMS
      • Админки/CRM
      • WAF
      • GraphQL
      • Virtual Hosts
      • OAUTH/OpenID/2FA
        • Общие рекомендации для авторизации
        • 2FA
        • OAuth 2.0
          • About
          • Definitions
          • Flows
            • Server Side App Authorization Flow
            • Single Page App Auhtorization Flow
            • Mobile and Native Apps Authorization Flow
            • Authorization Flow
            • Access Tokens Flow
              • Authorization Code Request
              • Password Grant
              • Client Credentials
              • Access Token Reponse
              • Access Token Lifetime
              • Refreshing Access Tokens
              • Making Authenticated Requests
            • Listing Authorizations and Revoking Access Flow
            • OAuth for Browserless and Input Constrained Devices
            • PKCE
            • Token Introspection Server Flow
          • Vulnerabilities
        • OpenID Connect (OIDC)
        • IndieAuth
        • Разница между OAuth и OpenID
        • JWT
      • Servers
    • Покупка SIM-карт и номеров
    • Banks & Payments
    • Программы лояльности
    • Digital Rights Management (DRM)
    • ELK — Elasticsearch, Logstash, Kibana
    • 1C
    • CI/CD
    • SCM
    • Honeypots
    • ChatGPT
  • Learning
    • Компетенции
    • Материалы SANS & Offensive Security
    • Просто норм материалы/gitbooks по пентесту вцелом...
    • Platforms & Playground Labs
    • Бумажная ИБ
  • Bug Bounty
    • Notes
    • Browser Plugins
    • Cheat Sheets
    • Платформы
    • Specific tools
  • Hardware/IoT
    • Tools
    • Training
    • Papers & Books
Powered by GitBook
On this page

Was this helpful?

  1. Technologies
  2. WEB
  3. OAUTH/OpenID/2FA
  4. OAuth 2.0
  5. Flows

Access Tokens Flow

Authorization Code RequestPassword GrantClient CredentialsAccess Token ReponseAccess Token LifetimeRefreshing Access TokensMaking Authenticated Requests
PreviousAuthorization FlowNextAuthorization Code Request

Last updated 4 years ago

Was this helpful?