Compare the main OAuth flows Salesforce supports and tell me how you choose between them.
Suggested answer
I choose by constraint rather than by name, because that is how the requirement arrives.
• Authorisation code flow (web server flow) — a user is present and the client can protect a secret. Server-side web applications.
• Authorisation code flow with PKCE — a user is present but the client cannot protect a secret. Single-page applications and native mobile apps. This has replaced the older user-agent (implicit) flow, which returned the token in a URL fragment.
• JWT bearer flow — no user present, no password permitted. Server-to-server integrations, signed with a certificate, with the user pre-authorised on the connected app.
• Device flow — the device has no usable browser or keyboard. The user completes authentication on a second device while the first polls.
• Refresh token flow — not a way in, but how an existing grant is renewed without re-prompting.
• Client credentials flow — the application acts as itself against a designated run-as user, with no end user in the picture.
• Username-password flow — I name it so the panel knows I know it, and then say I do not use it: it stores the credential the rest of the model exists to eliminate, and Salesforce blocks it by default in newer orgs.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.