OAuth grant type
The defined procedure an OAuth 2.0 client follows to obtain an access token, such as the authorization code or client credentials grant; the implicit grant is now discouraged.
A grant type is the method an OAuth client uses to obtain an access token from the authorization server. RFC 6749 defines four, and allows extensions. The authorization code grant sends the user to the authorization server to sign in and approve access, then returns a short-lived code that the client exchanges for a token over a direct back-channel request. The implicit grant returned the token straight through the browser. The resource owner password credentials grant has the user give their password to the client. The client credentials grant lets an application obtain a token for itself, with no user involved, which suits service-to-service calls.
Practice has moved on since 2012. The OAuth 2.0 Security Best Current Practice (RFC 9700) advises against the implicit grant, because tokens exposed in the browser can leak, and says the password grant must not be used, because it hands the user’s password to the client and defeats the purpose of OAuth. The authorization code grant with PKCE is the commonly recommended default, including for mobile and browser applications.
Exam relevance: a scenario is likely to describe an application type and ask which grant fits. Candidates are expected to match user sign-in to the authorization code grant with PKCE, machine-to-machine access to client credentials, and to recognise the implicit and password grants as legacy choices.