Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: ✉️ documental bug for Implicit oAuth2 flow

Implicit grant type is used to obtain access tokens if your application (client) is a mobile application or a browser based app such as a JavaScript client. Similar to authorization code grant, the implicit grant type is also based on redirection flow. The redirection URI includes the access token in the URI fragment. Therefore, the client application is capable of interacting with the resource owner user agent to obtain the access token from the redirection URI which is sent from the authorization server.

The implicit grant type does not require client authentication, and relies on the presence of the resource owner and the registration of the redirection URI. The resource owner is authenticated by the authorization server to obtain the access token. The access token is encoded into the redirection URI. This may be exposed to the resource owner and other applications residing inside the same device.

The diagram below depicts the flow of Implicit Grant.

  1. The client requests for the access token with the client ID and grant type, and other optional parameters.

  2. Since the resource owner authenticates directly with the authorization server, their credentials will not be shared with the client.

  3. The Authorization Server sends the access token through a URI fragment to the client.

  4. The client extracts the token from the fragment and sends the API request to the Resource Server with the access token.

Note

The refresh token will not be issued for the client with this grant, as the client type is public. Also note that, the Implicit grant does not include client authentication use the client secret of the application

The following parameters are required to implement the Implicit grant type in WSO2 API Manager.

NameDescriptionSample value
scopeThe scope used to implement the grant typeopenid
response_typeThe required response formatid_token+token
redirect_uriThe URL of the default playground applicationhttp://localhost:8080/playground2/oauth2client&
nonceAny random value13e2312637dg136e1&
client_idCliend ID2i5sZA2gYhFwq2T2lbbJlQ_utwYa


Invoking the Token API to generate tokens  

...