
Series
Build an OAuth2 Authorization Server
Fourteen parts, from an empty Spring Boot project to a production-oriented OAuth 2.1-style and OpenID Connect authorization server: PKCE, JWT, refresh rotation, PostgreSQL, user and client administration, revocation, Docker and CI.
- 15 parts
- 12 hours total
- beginner to intermediate to advanced
- Java 25 · Spring Boot 4 · Spring Security · PostgreSQL
Foundations
2 parts- The planWhat we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out. about 10 minutes, reading only beginner
- The mental modelOAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code. about 25 minutes, reading only beginner
A working server
2 parts- A server that startsSpring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints. about 45 minutes intermediate
- Authorization Code and PKCE, by handRun the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier. about 40 minutes intermediate
Persistence and identity
3 parts- State that survives a restartMove registered clients, authorizations and consent into PostgreSQL, with Flyway owning the schema. about 60 minutes intermediate
- Users in the databaseReplace the in-memory user with JPA entities, roles, and a database-backed UserDetailsService that accepts username or email. about 60 minutes intermediate
- Registration, errors and dev dataA registration API with validation, one consistent error format, and demo credentials that only exist in the dev profile. about 45 minutes intermediate
Administration and security
3 parts- Managing clients and scopesADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token. about 90 minutes advanced
- Real tests and stable keysIntegration tests against real PostgreSQL with Testcontainers, and RSA signing keys that survive a restart. about 60 minutes advanced
- Accounts, passwords and lockoutUser administration, self-service and admin password changes, and a temporary lockout after repeated failed logins. about 75 minutes advanced
Completing the protocol
2 parts- ID tokens and UserInfoScope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them. about 45 minutes advanced
- Revoking a JWTToken revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately. about 45 minutes advanced