Web: OAuth 2.0
OAuth 2.0 powers 'Sign in with Google' and countless third-party integrations, but its roles and flows confuse even experienced developers. This quiz tests whether you understand what's actually happening.
Questions cover the core roles (client, resource owner, authorization server, resource server), the Authorization Code flow, access and refresh tokens, scopes, and why PKCE matters for public clients.
Could you explain the Authorization Code flow step by step? This quiz will find out.
Start quiz →
Opens in a new tab on Cletica
Sample questions3 of 10 shown
Q1
Which entity in OAuth 2.0 is the application requesting access on behalf of the user?
Q2
What does the 'scope' parameter in OAuth 2.0 define?
Q3
Which OAuth 2.0 component is responsible for issuing access tokens?
What This Quiz Covers
- Core roles: client, resource owner, authorization server
- The Authorization Code flow
- Access tokens vs. refresh tokens
- Scopes and what they define
- PKCE and why it matters
- OAuth 2.0 vs. OpenID Connect (OIDC)
Cletica
Want to create your own quiz?
Build surveys and quizzes, share with anyone, collect responses — free to start.
Try Cletica for free →