Implicit Grant

Description

Implicit Grant flow it's alternative for Authorization Code flow without client_secret. This flow instead of obtaining securecode just receives access_token in query string fragment. It's for client-side apps use in order to access an API, typically as Web SPA applications. For more detailed information read OAuth2.0 specifcation.

Basic scheme

get
Authorization Endpoint

[base]/auth/authorize
Obtaining access token
Request
Response
Query Parameters
state
optional
string
a value used by the client to maintain state between the request and callback
scope
optional
string
scope of the access request
redirect_uri
optional
string
client redirect URI
client_id
required
string
client ID
response_type
required
string
value MUST be set to token
302: Found
Redirect
[redirect_uri]#access_token=YzI3ZjQ1M2MtYzFlYi00ZjI3LWI2MzgtOTQ0MWI0ZmIzZjBi&state=eyJoYXNoIjoiIy9pbXBsaWNpdC9iYXNpYyIsImZvcm0tZGF0YSI6eyJ0eXBlIjoiYmFzaWMiLCJiYXNpYyI6eyJjbGllbnQtaWQiOiJpbXAtY2xpZW50In19LCJmb3JtLXBhdGgiOiJpbXBsaWNpdC1wYWdlIn0%3D

After this request you will be redirected to Log-in/Sign-up page

Example

Next step is granting access

Example

After allowing you will redirect to your application with access_token in query string fragment.

Example

Request
Response
curl -X GET \
'http://localhost:8081/auth/authorize?
state=example
&client_id=imp-client
&redirect_uri=http%3A%2F%2Flocalhost%3A3449%2Fauth.html
&response_type=token'
HTTP/1.1 302 Found
Location: http://localhost:3449/auth.html#access_token=ZGE0ZmQzZTYtOGU0OC00MDJhLWFkN2ItZTg5ZmViYjdmNTQ2
&state=example
Client
Second Tab
POST /Client
id: imp-client
resourceType: Client
grant_types:
- implicit
auth:
implicit:
redirect_uri: http://localhost:3449/auth.html