security OAuth2 & OpenID Tokens Explained | Access, ID, Refresh & Opaque Tokens josedacruz, September 1, 2025September 1, 2025 In this video, José Cruz breaks down everything you need to know about OAuth2 and OpenID Connect tokens. We’ll cover the key players in the authorization flow, explore different types of tokens (Access, ID, Refresh, Opaque), and compare JWT vs Opaque tokens. You’ll also learn real-world use cases, security best… Continue Reading
security OAuth 2.0 Device Authorization Flow Explained: Secure Login for Smart TVs, CLI Tools & IoT Devices josedacruz, July 27, 2025July 27, 2025 Tired of typing your email and password on a smart TV with a remote? In this video, you’ll learn how the OAuth 2.0 Device Authorization Flow solves login on input-constrained devices like TVs, CLI tools, printers, and IoT gadgets. We’ll walk through real-world examples, an easy-to-understand flow diagram, and Python… Continue Reading
security OAuth 2.0 Client Credentials Flow Explained 🔐 | Machine-to-Machine Auth in Depth josedacruz, July 16, 2025July 16, 2025 Welcome to part of our OAuth2/OpenID series! In this video, we explore the Client Credentials Flow — the go-to choice when your applications need to authenticate without any user interaction. Think machine-to-machine communication, microservices, daemon apps, and backend-only access. This video is one of six deep dives into the major… Continue Reading
security OpenID Connect Hybrid Flow: A Blend of Authentication & Authorization josedacruz, July 11, 2025July 11, 2025 Welcome to the third video in our 6-part series on OAuth2 and OpenID Connect flows! In this episode, we dive deep into the Hybrid Flow — a powerful but often overlooked approach that combines the strengths of Authorization Code and Implicit Flow. If you’re building SPAs or managing legacy auth… Continue Reading
security OAuth 2.0 Implicit Flow – Why It’s Deprecated and What We Learned josedacruz, July 9, 2025July 9, 2025 Welcome to another episode in our OAuth 2.0 Video Series!In this video, we deep dive into the OAuth 2.0 Implicit Flow — once popular with Single-Page Applications (SPAs), now officially deprecated. You’ll understand: Whether you’re a developer, architect, or security-conscious engineer, this lesson will help you appreciate how OAuth has… Continue Reading
security OAuth 2.0 Authorization Code Flow & OpenID Connect – Complete Walkthrough josedacruz, July 7, 2025July 7, 2025 Welcome! This video is a full breakdown of OAuth 2.0’s most secure flow — the Authorization Code Flow — along with the powerful identity layer that is OpenID Connect (OIDC). We take you step-by-step through how apps can securely get access to user data without ever seeing passwords, and how… Continue Reading
security Day 2 – OAuth2 in One Picture: The 4 Flows josedacruz, June 11, 2025June 11, 2025 Ever feel confused by OAuth2? In this video, we simplify everything into one visual map. No deep code or jargon — just the big picture. Perfect for developers, architects, and curious tech minds who want to understand why the flows exist and how they differ. 🧠 What You’ll Learn 🧭… Continue Reading
security Day 1 – Why OAuth2 Exists: The Real Problem It Solves josedacruz, June 3, 2025June 3, 2025 Welcome to Day 1 of Learn OAuth2 in 30 Days! 🎓In this kickoff episode, we answer a fundamental question: Why does OAuth2 exist at all? You’ll discover the real-world problem OAuth2 was designed to solve, the players involved in the protocol, and how it offers secure delegated access without exposing… Continue Reading