Suggested answer

I choose by constraint rather than by name, because that is how the requirement arrives.

• Authorisation code flow (web server flow) — a user is present and the client can protect a secret. Server-side web applications.
• Authorisation code flow with PKCE — a user is present but the client cannot protect a secret. Single-page applications and native mobile apps. This has replaced the older user-agent (implicit) flow, which returned the token in a URL fragment.
• JWT bearer flow — no user present, no password permitted. Server-to-server integrations, signed with a certificate, with the user pre-authorised on the connected app.
• Device flow — the device has no usable browser or keyboard. The user completes authentication on a second device while the first polls.
• Refresh token flow — not a way in, but how an existing grant is renewed without re-prompting.
• Client credentials flow — the application acts as itself against a designated run-as user, with no end user in the picture.
• Username-password flow — I name it so the panel knows I know it, and then say I do not use it: it stores the credential the rest of the model exists to eliminate, and Salesforce blocks it by default in newer orgs.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.