Authentication

The Wonderful Wizard of OAuth

Grant types, consent screens, and the yellow brick road to delegated access

L. Frank Baum · 21 July 2026

Pay no attention to the man behind the identity provider, unless he is asking for the implicit flow.

Baum's accessible guide leads readers through OAuth 2.0 and OpenID Connect without pretending that either was discovered by accident in a cornfield. It explains authorisation codes, PKCE, refresh tokens, consent, resource servers, and the repeated disappointment of confusing authentication with authorisation.

Contents

  1. No Place Like localhost
  2. The Scarecrow Requests the Correct Scope
  3. Emerald City as an Authorisation Server
  4. There and Back Again with a Refresh Token

Published by Austenpunk, the distinguished imprint for engineers who believe that every production incident would be improved by a stronger sense of narrative irony.

This essential volume combines literary feeling, technical anxiety, and just enough documentation to suggest that somebody once understood the system.

Cover of The Wonderful Wizard of OAuth
× Cover of The Wonderful Wizard of OAuth