Question 1
During the final step in the OAuth2 authorization process, what must the client send to the OAuth authorization server to obtain a data access token?
During the final step of the OAuth2 authorization process, the client must send the following to the OAuth authorization server to obtain a data access token:
- Authorization Code: The code received from the authorization server in the previous step.
- Client ID: The unique identifier for the client application registered with the authorization server.
- Client Secret: A confidential credential known only to the client and authorization server (sent securely, typically in the request body or HTTP Basic Auth header).
- Redirect URI: The callback URL where the authorization code was delivered, must match the registered redirect URI.
- Grant Type: Set to
authorization_codeto specify the OAuth2 flow being used.
Method: This request is made directly from the client's backend server to the authorization server's token endpoint using HTTPS POST, ensuring the client secret is transmitted securely and never exposed to the user's browser.
Upon validation of these parameters, the authorization server returns the access token, which the client can then use to access protected resources on behalf of the user.
















