Introducing IdentiFlows.dev: A Visual Reference for Identity Flows
Every developer who has played with OAuth 2.0 or OpenID Connect knows this moment: you need to double-check the exact sequence of a flow, and the diagram you remember seeing is scattered somewhere between a spec, a blog post, and a slide deck from a conference two years ago. The mechanism is well documented, but finding the right picture of it, at the right moment, is not. That is the gap I built…
Developers seeking to understand the precise sequence of identity protocols like OAuth 2.0 or OpenID Connect often struggle to locate the relevant diagram, as it is frequently scattered among various resources. To address this issue, Identity Flow Diagrams was created—a website offering developers and architects a convenient visual reference for the sequence diagrams of common identity protocols.
The site provides each flow with a concise introduction, a sequence diagram illustrating the entire exchange, and a detailed step-by-step breakdown.
Currently, Identity Flow Diagrams is divided into four categories: User Login & SSO, Application & API Security, Security Enhancements, and Others, encompassing eight flows. These include the OAuth 2.0 Authorization Code flow (and PKCE variant), OpenID Connect Authorization Code flow with PKCE (the recommended login flow for most modern applications), OpenID Connect Implicit flow (marked as deprecated), SAML 2.0 SP-Initiated SSO, the OpenID Connect Discovery flow, and the DPoP-Bound Access Token Request and Usage.
While the initial release focuses on the most frequently requested flows, future additions are planned, including the OAuth 2.0 Client Credentials flow, OAuth 2.0 Device Authorization flow, and WebAuthn for passwordless authentication. The project is in its early stages and welcomes feedback from users to ensure accuracy and clarity.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.