# Authorization code flow

The web applications that request API resources through their servers follow through the authorization code flow to obtain authorization code. That further exchanges with the authorization server to receive access and refresh tokens. Also, the implementation of authorization code flow for web applications provides crucial security benefits such as client authentication before producing authorization code and server-to-server communication without exposing tokens to others.

The flowchart below illustrates the authorization code grant flow, where an access token is generated, and then used in an API request:

- As a prerequisite, [register your application](https://www.bigin.com/developer/docs/apis/v2/register-client.html) with the authorization server to get client credentials such as _client ID_ and _client secret_. These credentials are helpful to the authorization server in identifying your application while getting authorization code and access tokens.
- The actual flow starts from here. In the _first step_, you must [create an authorization request link](https://www.bigin.com/developer/docs/apis/v2/auth-request.html) and provide a way for the user to open the authorization request link.
- In the _second step_, the [user who owns the resources must authorize the request](https://www.bigin.com/developer/docs/apis/v2/request-user-grant-permissions.html) by validating the scopes. If the user has already signed in, then the authorization consent page appears automatically. If not, you must sign in first and then either accept or reject the authorization request.
- When the user accepts an authorization request, your application will get an authorization code. In the _third step_, you must [request access tokens in exchange for an authorization code](https://www.bigin.com/developer/docs/apis/v2/access-refresh.html).
- Your application receives access and refresh tokens. In the _fourth step_, you can [send an API request using the access token](https://www.bigin.com/developer/docs/apis/v2/use-access-token-api-request.html) for accessing resources.
- The access token is a short-lived key that needs to be refreshed. In the _fifth step_, you can [use the refresh token to generate a new access token](https://www.bigin.com/developer/docs/apis/v2/refresh.html).
- In the _last step_. you can [revoke your refresh token](https://www.bigin.com/developer/docs/apis/v2/revoke-tokens.html) that invalidates your application to access resources. This step is optional and can only be performed when the key tokens are compromised.
