Resource owner password

The resource owner credentials are similar to the client credentials flow, with the difference being that, in this case, the resource owner credentials are used to access a protected resource owned by the resource owner.

In this flow, the resource owner exchanges credentials with the client application via a user-agent, for example, a mobile application or a web application. The application then uses the credentials to authenticate against the authorization server to obtain an access token, then used to access a protected resource.

This flow is also referred to as a two-legged OAuth as even though a user-agent may be present to enter the user credentials, there is not authorization required by the resource owner for ...

Get Implementing Oracle API Platform Cloud Service now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.