oauth2

7 posts.

5 min

A server that starts

Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.

  • spring-boot
  • spring-security
5 min

Authorization Code and PKCE, by hand

Run the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier.

  • oauth2
  • pkce
5 min

Managing clients and scopes

ADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token.

  • spring-security
  • oauth2
2 min

References

Every specification and document the series relies on, grouped by subject.

  • oauth2
  • oidc
4 min

Revoking a JWT

Token revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately.

  • oauth2
  • jwt
6 min

The mental model

OAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code.

  • oauth2
  • oidc
5 min

The plan

What we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out.

  • oauth2
  • oidc