Apex Hours - OAuth 2.0

Introduction to OAuth 2.0

Covers general concepts, and gives an intro to each of the flows covered in other videos. It's just the first 8 minutes or so this time until the video moves into the details of the web server flow.

 

Details of Flows

As with SSO, the OAuth 2.0 videos concentrate on one or two flows per video, walking through the main steps as well as summarising pre-requisites, and exploring important aspects to consider around choosing and configuring these flows. There's particular attention paid to security considerations where these are relevant.

Here and there you'll find some concrete recommendations - avoiding username password and treating user-agent with some caution for example - which to my knowledge are as true today as when they were recorded in 2021, however please add comments to the youtube comments if there's anything you'd like to point out!

AUTHORISATION CODE WITH SECRET (WEB SERVER)

Cloud Sundial article

Apex Hours article

IMPLICIT GRANT (USER-AGENT)

Cloud Sundial article

Apex Hours article

AUTHORISATION CODE WITH PKCE

Cloud Sundial article

Apex Hours article

JWT / SAML BEARER FLOWS

Cloud Sundial article - JWT Bearer

Cloud Sundial article - SAML Bearer

Apex Hours article

USERNAME-PASSWORD FLOW

Cloud Sundial article

Apex Hours article

Comparison and Decision Guide

So as with SSO, the aim of this video is to discuss the important considerations and indicate which flow might be right for a given circumstance:

Apex Hours article