November 2017
Intermediate to advanced
542 pages
14h 24m
English
The resource owner password grant type, defined in RFC 6749, Section 4.3 (https://tools.ietf.org/html/rfc6749), can be used directly as an authorization grant to obtain access_token and, optionally, refresh_token. This grant is used when there is a high degree of trust between the user and the client and when other authorization grant flows are not available. This grant type eliminates the need for the client to store the user credentials by exchanging the credentials with a long-lived access_token or refresh_token.
Read now
Unlock full access