Urgent.News

What's breaking now, across thousands of outlets.

Tech

Introducing IdentiFlows.dev: A Visual Reference for Identity Flows

Every developer who has played with OAuth 2.0 or OpenID Connect knows this moment: you need to double-check the exact sequence of a flow, and the diagram you remember seeing is scattered somewhere between a spec, a blog post, and a slide deck from a conference two years ago. The mechanism is well documented, but finding the right picture of it, at the right moment, is not. That is the gap I built…

Developers seeking to understand the precise sequence of identity protocols like OAuth 2.0 or OpenID Connect often struggle to locate the relevant diagram, as it is frequently scattered among various resources. To address this issue, Identity Flow Diagrams was created—a website offering developers and architects a convenient visual reference for the sequence diagrams of common identity protocols.

The site provides each flow with a concise introduction, a sequence diagram illustrating the entire exchange, and a detailed step-by-step breakdown.

Currently, Identity Flow Diagrams is divided into four categories: User Login & SSO, Application & API Security, Security Enhancements, and Others, encompassing eight flows. These include the OAuth 2.0 Authorization Code flow (and PKCE variant), OpenID Connect Authorization Code flow with PKCE (the recommended login flow for most modern applications), OpenID Connect Implicit flow (marked as deprecated), SAML 2.0 SP-Initiated SSO, the OpenID Connect Discovery flow, and the DPoP-Bound Access Token Request and Usage.

While the initial release focuses on the most frequently requested flows, future additions are planned, including the OAuth 2.0 Client Credentials flow, OAuth 2.0 Device Authorization flow, and WebAuthn for passwordless authentication. The project is in its early stages and welcomes feedback from users to ensure accuracy and clarity.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

A Practical Checklist for Debugging a Broken API Request (With Free Browser Tools)

You send a request. You get a 401 . Or a 400 . Or an empty response and a vague error. Most API bugs come from a small set of causes: a malformed token, bad encoding, wrong headers, or a network…

  • Reproduce request with cURL using -i flag for headers
  • Inspect status code for specific error meaning
  • Decode JWT parts to check expiration and audience

I Built an Open-Source J1939 CAN Bus Emulator (Because Vector Tools Cost Too Much)

If you've ever tried to test J1939 diagnostics tooling, integrate a telematics app, or just learn how heavy-duty vehicle networks work, you've probably hit the same wall I did: the real tools are…

  • Open-source J1939 CAN bus emulator created to address expensive, closed testing tools
  • CLI and GUI versions available, with Docker support for CI/CD and cloud infrastructure
  • GUI allows hardware selection, baud rate configuration, PGN setting, and real-time monitoring

A shipping exception queue that ages, deduplicates and can be claimed

Most ecommerce backends model shipments as a happy path with a status column. label_created → in_transit → delivered . When something goes wrong, the row gets stuck at whatever it was last stuck at…

  • Exception queue manages stuck shipments in destination depots
  • Shipmentexception table includes id, kind, dedupekey, and state columns
  • Dedupekey prevents queue growth from repeated webhooks

More from Wednesday 30 September →