Skip to main content

Choosing the right flow

Decision tree​

                    ┌─────────────────────────────┐
│ What kind of application? │
└─────────────────────────────┘
│
┌─────────────────────┼─────────────────────┐
│ │ │
▼ ▼ ▼
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ Server-side web │ │ SPA / mobile │ │ Backend service │
│ application │ │ application │ │ (no user) │
└─────────────────┘ └─────────────────┘ └─────────────────┘
│ │ │
▼ ▼ ▼
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ Authorization │ │ Authorization │ │ Client │
│ Code Flow │ │ Code + PKCE │ │ Credentials │
└─────────────────┘ └─────────────────┘ └─────────────────┘

Flow comparison​

FeatureAuth CodeAuth Code + PKCEClient Credentials
User authenticationYesYesNo
Refresh tokensYesYesNo
Requires a client secretYesNoYes
Suitable for frontendsNoYesNo
User consentYesYesNo
Returns an ID tokenYesYesNo

Recommendations by application type​

Application typeRecommended flowNotes
Traditional web app (PHP, Rails, Django, ASP.NET)Authorization CodeStore tokens on the server
Single Page Application (React, Vue, Angular)Authorization Code + PKCENo backend required
Mobile app (iOS, Android)Authorization Code + PKCEUse a custom URL scheme
Native desktop applicationAuthorization Code + PKCEUse a localhost redirect
Backend service / cron jobClient CredentialsNo user context
Microservice-to-microservice communicationClient CredentialsService-account access

Quick summary​