The implicit grant type does not require client authentication, and relies on the presence of the resource owner and the registration of the redirection URI. The resource owner needs to authenticate with is authenticated by the authorization server to obtain the access token. Because the The access token is encoded into the redirection URI, it . This may be exposed to the resource owner and other applications residing in inside the same device.
The diagram below depicts the flow of Implicit Grant.
The client requests for the access token with the client ID and grant type with , and other optional parameters.
Since the resource owner authenticates directly with the authorization server, his/her their credentials will not be shared with the client.
The Authorization Server sends the Access access token in through a URI fragment to the client.
Client extract The client extracts the token from the fragment and send sends the API request to the Resource Server with the access token.
With this grant, the The refresh token will not be issued for the client with this grant, as the client type is public. Also note that , the implicit Implicit grant does not include client authentication because it does not make use of the client secret of the application
The following parameters are required to implement the Implicit grant type in WSO2 API Manager.
The OAuth scope you are requesting for the particular token
|The required response format|
The URL of the Oauth application requesting for the token
|Any random value|
|Client ID of the OAuth application|
An example is given below :
https://localhost:8243/authorize scope=openid &response_type=id_token &redirect_uri=http://localhost:8080/playground2/oauth2client &nonce=13e2312637dg136e1 &client_id=mzdQQ0RZOIqAf549ucIImB4h0SIa
Invoking the Token API to generate tokens
In his this example we are using use the WSO2 Playground, which is hosted as a web application, to obtain the access token with implicit grant.
The following instructions use the sample playground webapp. See For instructions on how to set up the sample webapp, see Setting up the Sample Webapp and follow the steps to setup the sample webapp.
- Login to WSO2 API Manager Store and create an application as shown below.
the Production keys tabin
. Add http://localhost:8080/playground2/oauth2client as thecallback URL, select implicit from the Grant Types
Callback URL. Select Implicit from the list of grant types and click Generate Keys.
The Implicit grant and Code grant type checkboxes are disabled by default in the UI. To enable selecting the checkboxes, enter the Callback URL for the application.
- Go to playground app http://wso2is.local:8080/playground2/index.jsp and click click import photos.
Give the information in the table below and click Authorize.
Field Sample Value Authorization Grant Type
Implicit Client Id Consumer Key obtained for your application Scope The scope you have selected for you application Callback URL The callback URL of your application Authorize Endpoint
The playground application redirects to the login page. Enter you username and password and click Sign In.
Click Approve to provide access to your information.
You will receive the access token as follows
For users to be counted in the Registered Users for Application statistics, which takes the number of users shared each of the Application, they have to generate access tokens using Password Grant type.