Flow 01 · Sign-in
Authorization code with PKCE.
OpenID Connect is OAuth plus an ID token. The code comes back through the browser. The tokens go server to server. Once you see that split, the rest of the checks make sense.
Watch for
- The verifier stays on your app. Only the S256 challenge goes in the redirect.
stateis how you recognise your own response.nonceis how you know the ID token belongs to this login.- As of draft 16, the authorization server also sends
isson the way back.
Failure modes
- An access token sitting in the redirect URL. That’s the implicit grant, and OAuth 2.1 leaves it out.
- Trusting an ID token because it decodes. Check the issuer, the audience, the nonce, and the signature.
- Matching the redirect URI with a prefix or a wildcard. OAuth 2.1 wants an exact string.