100% Free Forever
AI-Powered Learning
Industry Expert Content
Certificates & Badges
Learn At Your Own Pace
Programming

Choosing the Right Grant

OAuth 2.0 offers several grant types built for different trust boundaries; picking the wrong one is one of the most common real-world sources of OAuth vulnerabilities.

Grant TypesIntermediate9 min readJul 10, 2026
Analogies

The Core Question: Who Is the Actor?

Every grant selection decision reduces to one question: is there a human resource owner delegating access, or is the client acting purely as itself? If a specific user needs to grant an application access to their own data, that's Authorization Code with PKCE, full stop, regardless of whether the client is a web app, SPA, or mobile app. If there's no user at all, a backend job talking to another backend service, that's Client Credentials. Almost every OAuth misconfiguration traces back to conflating these two cases: using Client Credentials where per-user delegation was actually needed, or building a custom non-standard flow because a team wasn't sure which standard grant fit.

🏏

Cricket analogy: It's like deciding whether a substitute fielder needs the captain's specific on-field authorization for that match (a delegated, person-specific grant) versus a groundstaff member who just needs their own staff badge to enter the facility, no captain involved at all.

A Practical Decision Framework

In practice: web apps with a server-side back end and browser-based SPAs and mobile apps should all use Authorization Code with PKCE for anything involving a logged-in user, the difference is only in where the code exchange happens (server-side directly, or via a BFF for SPAs). Backend services calling other backend or third-party APIs with no user context use Client Credentials. Devices with limited or no input capability, smart TVs, CLI tools without a browser, use the Device Authorization Grant (not covered in depth here, but worth knowing it exists specifically for that case). Anything reaching for the Implicit or Password grants should stop and reconsider, per the deprecated-grants discussion, there is essentially always a better modern option.

🏏

Cricket analogy: It's like a team having a clear playbook: a specific batter walking to the crease follows the standard umpire sign-in procedure (Authorization Code), while the groundskeeper follows a totally different facility-access procedure (Client Credentials), and nobody improvises a third, undocumented way in.

Scoping and Least Privilege Across Grants

Whichever grant you choose, scope design should follow least privilege: request only the specific permissions the current operation needs, not a broad 'everything' scope out of convenience. A read-only reporting dashboard should request orders:read, not orders:write or admin:*; a Client Credentials service that only reorders inventory should never also carry a scope that lets it issue refunds. This matters doubly for Authorization Code flows, where overly broad scope requests also erode user trust at the consent screen, users are more likely to abandon a login flow that asks for access it clearly doesn't need for its stated purpose.

🏏

Cricket analogy: It's like giving a substitute fielder specific permission to field at deep cover for one over, not a blanket pass to bowl, bat, and make tactical decisions for the rest of the match; the access should match the exact job at hand.

text
Decision checklist:

1. Is a specific human user delegating access to their own data/actions?
   -> YES: Authorization Code + PKCE
        - Web app with server back end: exchange code server-side
        - SPA: exchange code via CORS-enabled /token, or better, a BFF
        - Native/mobile app: exchange code in-app, PKCE mandatory
   -> NO, continue to 2.

2. Is this a backend/service calling another API with no user context?
   -> YES: Client Credentials

3. Is this a device with no/limited browser or keyboard input
   (smart TV, CLI without local browser, IoT)?
   -> YES: Device Authorization Grant

4. Are you about to reach for Implicit or Password (ROPC)?
   -> STOP. Re-evaluate against options 1-3; a fitting modern
      grant almost always exists.

A related but distinct pattern worth knowing: when a backend service needs to call a downstream API on behalf of a user who already authenticated to it (not itself), the right tool is typically token exchange (RFC 8693) or an 'on-behalf-of' flow, not Client Credentials with a bolted-on user_id parameter. This preserves the original user's identity and scope constraints through the whole call chain.

Red Flags in a Grant Selection Review

When reviewing an OAuth integration, several signals reliably indicate a wrong grant choice: a Client Credentials token being used with a caller-supplied user or account ID parameter (should be Authorization Code or token exchange); a mobile or SPA app embedding a client_secret in its binary or bundle (the app is public, so it needs PKCE, not a secret it can't actually protect); a backend prompting users to type their password into a custom form that then calls another provider's API (ROPC in disguise, likely violating that provider's terms of service); and any homegrown 'bearer token' scheme invented because a team found OAuth's standard grants 'too complicated' for their use case, which usually means missing expiration, rotation, or scope enforcement entirely.

🏏

Cricket analogy: It's like a review flagging a groundstaff pass being used to admit a specific spectator by name, a clear sign the wrong kind of pass is being used for the wrong job, and the spectator should have gone through the normal ticketing gate instead.

If a design doc says 'we'll just use Client Credentials and pass the user ID as a parameter', that is almost always a red flag for an authorization bypass waiting to happen. The fix is nearly always Authorization Code with PKCE (if a user is present and interactive) or token exchange/on-behalf-of (if a backend needs to relay an already-authenticated user's identity downstream).

  • The first question in grant selection is always whether a specific human resource owner is delegating access, or whether the client is acting purely as itself.
  • Authorization Code with PKCE covers essentially every user-facing login scenario across web, SPA, and mobile clients.
  • Client Credentials is for backend-to-backend calls with no user context, never for fetching per-user data via an ID parameter.
  • Device Authorization Grant exists specifically for input-constrained devices like smart TVs and CLI tools.
  • Implicit and Password (ROPC) grants should be treated as deprecated red flags, not viable options, in any new design.
  • Least-privilege scoping applies to every grant: request only the exact permissions the current operation needs.
  • Token exchange (RFC 8693) or on-behalf-of flows, not Client Credentials with a bolted-on user ID, is the correct pattern for relaying user identity through a service chain.

Practice what you learned

Was this page helpful?

Topics covered

#Programming#OAuth20StudyNotes#ChoosingTheRightGrant#Choosing#Right#Grant#Core#StudyNotes#SkillVeris#ExamPrep

Frequently Asked Questions

21 categories · pick one to explore

Where can I get free study notes for programming and tech subjects?
SkillVeris offers completely free study notes covering programming and tech subjects, with no signup fees or paywalls. The notes are structured by course and topic, written for quick understanding, and enriched with the Learn Through Hobbies analogy method, so you can revise concepts through cricket, music, gaming, cooking and more.
Are SkillVeris study notes good for exam revision?
Yes, the study notes are designed for efficient revision: each topic answers its heading immediately, keeps explanations concise, and links to related glossary terms and cheat sheets. Students preparing for university exams or certification tests use them as quick revision notes because they distil concepts without the padding of full textbooks.
What subjects do the free study notes cover?
The study notes span the platform's main domains, including AI and machine learning, Python and programming, web development, DevOps, cloud, security and databases. Coverage mirrors the 37 live courses, so notes exist for the topics you are actually studying, and new note sets are added as courses launch.
How are SkillVeris study notes different from regular textbooks?
The notes are answer-first, concise and free, whereas textbooks are long and often expensive. Each section explains one concept directly, then reinforces it through selectable hobby analogies like cricket or cooking. Notes also cross-link to the glossary, blog and cheat sheets, letting you jump to related material instantly instead of flipping pages.
Can I use the developer study material without creating an account?
The study notes are free to access, and SkillVeris does not charge anything for its developer study material at any point. Browsing notes is straightforward from the Study Notes section, and if you want progress tracking, certificates and AI Mentor conversations tied to your learning, a free account unlocks those extras.
Do the study notes explain concepts with analogies?
Yes, this is a signature SkillVeris feature. Study notes use the Learn Through Hobbies method, explaining technical concepts through analogies from twelve domains including cricket, music, gaming, photography, travel, movies, fitness, chess, cooking, finance, business and sports. You can switch the analogy domain instantly to whichever hobby makes the concept click.
Are the revision notes suitable for last-minute exam preparation?
Yes, revision notes on SkillVeris work well for last-minute preparation because every section states the answer in its first sentences, so skimming is genuinely effective. Pair them with the relevant cheat sheet for formulas and syntax, and use the glossary for any unfamiliar term you meet while cramming.
Is there free study material for AI and machine learning?
Yes, SkillVeris provides free study notes across its AI and ML catalogue, covering Python for AI, deep learning frameworks like PyTorch and TensorFlow, Hugging Face Transformers, Large Language Models, RAG, AI agents and MLOps. All of it is free, making it a strong resource for Indian students and global learners alike.
Can beginners understand the study notes, or are they for experts?
Beginners can absolutely use them. The notes are written in plain language, define terms as they appear, and lean on hobby analogies to make abstract ideas concrete. Difficulty scales with the underlying course level, so beginner-course notes stay gentle while advanced-course notes go deeper, and the glossary supports you throughout.
How do study notes connect with SkillVeris courses?
Study notes are organised by course and topic, so they map directly to the structured courses and their 24–40-lesson curriculum. Many learners study a lesson first, then use the matching notes for revision before module assessments and the final exam, where 80 percent is required to pass and earn the certificate.
Are there study notes for Python specifically?
Yes, Python is well covered through notes tied to the Python-focused courses, including Python for AI and ML. Topics span fundamentals through applied machine learning usage. You can reinforce the notes with Python practice in Code Lab, which runs code in your browser with no installation required.
Do the study notes include code examples?
Yes, study notes include code examples wherever a concept is best shown in code, alongside explanations, key points and analogies. Reading a snippet in the notes and then reproducing it yourself in Code Lab is an effective loop, since Code Lab lets you run code in the browser across six languages.
How often is new study material added to SkillVeris?
Study material grows alongside the course catalogue. Whenever new courses join the platform's 37 live courses, matching study notes, glossary entries and cheat sheets are added so the resources stay in sync. Existing notes are also refined over time, so it is worth revisiting topics you studied earlier.
Can I use SkillVeris notes to prepare for technical interviews?
Yes, the notes make excellent interview revision because they compress each concept into direct, answer-first explanations, which mirrors how you should answer interview questions. Combine them with the SkillVeris interview questions feature, which includes readiness scoring, to test whether your revision has actually made you interview-ready.
Are the study notes mobile-friendly for studying on the go?
Yes, the study notes are built to load fast and read comfortably on mobile devices, so you can revise during a commute or between classes. Sections are short and answer-first, which suits small screens, and analogy switching works on mobile too, letting you study anywhere without carrying books.
What is the difference between study notes and cheat sheets?
Study notes explain concepts in depth with context, examples and analogies, making them ideal for learning and revision. Cheat sheets are compact quick-reference summaries of syntax, commands and key facts, ideal once you already understand a topic. Most learners study the notes first, then keep the cheat sheet handy while coding.
Do study notes help if I am stuck on a course lesson?
Yes, reading the matching study notes often clarifies a lesson because the same concept is explained from a different angle, frequently with a different analogy. If you are still stuck, ask the AI Mentor, which answers 24/7 at Quick, Detailed or Deep-dive depth until the idea genuinely makes sense.
Is there free study material for DevOps and cloud topics?
Yes, SkillVeris carries free study notes for DevOps and cloud topics as part of its coverage across 37 live courses. The material suits learners following the DevOps Engineer or Cloud Engineer paths, and it links to related glossary terms and cheat sheets so you can revise the whole toolchain in one place.
Can school or college students in India use these notes for projects?
Yes, students across India and worldwide use SkillVeris notes for coursework, projects and exam preparation, and everything is free, which matters for student budgets. The notes explain concepts clearly enough to cite in project reports, and Code Lab lets you prototype the project code directly in your browser.
How should I combine study notes with other SkillVeris resources?
A proven loop: learn from a course lesson, revise with the matching study notes, look up unfamiliar terms in the glossary, keep the cheat sheet open while practising in Code Lab, and quiz yourself with interview questions. The AI Mentor fills any remaining gaps 24/7, at whatever depth you need.

What Learners Say

Real journeys from the SkillVeris community — swipe for more.

SkillVeris taught me Python through Cricket. Now I’m building real projects and feeling confident!
Arjun S. · B.Tech Student
The best platform for hobby-based learning. Concepts finally stick.
Priya R. · Data Analyst
I went from zero coding to a portfolio of projects — all by learning through my love for gaming. Landed my first internship!
Kabir M. · CS Undergraduate
Trending Topics50 popular tags — tap to explore
Trending CoursesAll 37 free courses — tap to browse