Tools, FAQ, Tutorials:
Authentication Flows with Google OpenID Connect
What are Authentication Flows Supported by Google OpenID Connect service?
✍: FYIcenter.com
Google OpenID Connect service supports 3 Authentication Flows:
1. Implicit Flow - The Implicit Flow is simple to implement. But it is less secure. Authentication is done in a single call to Google OpenID Connect service, which returns the "id_token" containing user identity.
2. Authorization Code Flow (Server Flow) - The Authorization Code Flow is more complex to implement. But it is more secure. Authentication is done in two calls to Google OpenID Connect service. The first call returns only an authorization "code". You need to make a second call to exchange "code" for the final "access token".
3. Hybrid Flow, also called OAuth 2.0 Multiple Response Type Encoding Practices - In the Hybrid Flow, you ask for both "id_token" and authorization "code" in the first call. This allows you to mix the Implicit Flow and Authorization Code Flow together.
⇒ Google OpenID Connect Metadata Document
⇐ Application Registration for Google OpenID
2021-03-21, 1329🔥, 0💬
Popular Posts:
How to use the RSS Online Validator at w3.org? You can follow this tutorial to learn how to use the ...
How to create a navigation file like navigation.xhtml for an EPUB 3.0 book? At least one navigation ...
How to use "json-to-xml" Azure API Policy Statement? The "json-to-xml" Policy Statement allows you t...
How to use .NET CLR Types in Azure API Policy? By default, Azure imports many basic .NET CLR (Common...
How to use the "set-variable" Policy Statement to create custom variables for an Azure API service o...