Skip to content

Auth Flows Explained

Four ways to prove who a request is from: session cookies, JWT, OAuth2, and API keys, each shown as a live animated diagram, with a side-by-side comparison to help you choose.

Animated diagrams · 4 flows

Compare all 4

Sort by any column to find the right fit. Click a name to open its details.

API keyRequest → response (header)NoLowHTTP (custom header)LowServer-to-server, partner APIs
JWTRequest → response (Bearer)NoLowHTTP (Authorization header)MediumAPIs, stateless services, microservices
OAuth2Multi-step (client ↔ IdP ↔ API)NoHigher (handshake)HTTPS redirectsHighDelegated access, third-party login (Sign in with…)
SessionRequest → responseNoLowHTTP (Cookie header)LowFirst-party web apps, browsers