Every developer who has played with OAuth 2.0 or OpenID Connect knows this moment: you need to double-check the exact sequence of a flow, and the diagram you remember seeing is scattered somewhere between a spec, a blog post, and a slide deck from a conference two years ago. The mechanism is well documented, but finding the right picture of it, at the right moment, is not.
That is the gap I built Identity Flow Diagrams to close, with Auth0 and my team backing me along the way.
What It Is
Identity Flow Diagrams is a website with one job: give developers and architects a fast, visual reference for the sequence diagrams behind common identity protocols. Each flow gets its own page with:
- A short introduction explaining what the flow is for and when to use it.
- A sequence diagram showing the full exchange between the parties involved.
- A step-by-step breakdown of what happens at each stage.
The goal is simple: be faster than digging through the spec or your own memory of a documentation page you read six months ago.
What Is There Today
The website is currently organized into four categories: User Login & SSO, Application & API Security, Security Enhancements, and Others.
Right now, that covers eight flows:
- OAuth 2.0 Authorization Code flow (and its PKCE variant).
- OpenID Connect Authorization Code flow with PKCE, the recommended login flow for most modern apps.
- OpenID Connect Implicit flow, included and explicitly marked as legacy since it is deprecated in favor of Authorization Code with PKCE, although it's still used in some contexts.
- SAML 2.0 SP-Initiated SSO, one of the most used SAML flows in the enterprise context.
- OpenID Connect Discovery, for retrieving a provider's configuration and public keys.
- DPoP-Bound Access Token Request and DPoP-Bound Access Token Usage, covering the mechanism for binding a token to a specific key pair.
While a static diagram gives you an overview of the whole flow, the interactive mode allows you to go through the flow and learn what happens at each step:
This Is an Early Release
I want to be upfront about where the project stands: this is a very first release, not a finished project. This initial flow set reflects what developers ask about most often, not everything that belongs on the website eventually. A few flows I am planning to add very soon:
- OAuth 2.0 Client Credentials flow, for machine-to-machine scenarios.
- OAuth 2.0 Device Authorization flow, for browserless and input-constrained devices.
- WebAuthn, for passwordless authentication.
There is also a longer backlog behind those, including Token Exchange, Private Key JWT authentication, and many more.
I Would Like Your Feedback
This is exactly the point in a project where feedback is most useful, before the shape of things is locked in. If you try identiflows.dev and something is unclear, missing, or just wrong, I want to hear about it. Just drop a message in the comment section below.


Top comments (0)