Topic 3: The flow
21 min read·22 Sept 2026
B.1 The authorization code flow with PKCE
The server side is done: verify, advertise, refuse. Now let's follow a client through getting a token, because the design of the server only makes sense once you see what the client does with the 401.
MCP uses the OAuth 2.1 authorization code flow when a person is involved. In plain words:
- The client sends the user's browser to the authorization server with a request. The user signs in and approves.