CourseModel Context Protocol · Module 7: Authorization · part 42 of 83
Part 42 · Module 7: Authorization

Topic 3: The flow

21 min read·22 Sept 2026

B.1 The authorization code flow with PKCE

The server side is done: verify, advertise, refuse. Now let's follow a client through getting a token, because the design of the server only makes sense once you see what the client does with the 401.

MCP uses the OAuth 2.1 authorization code flow when a person is involved. In plain words:

  • The client sends the user's browser to the authorization server with a request. The user signs in and approves.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.