authentication/authorization/delegation entities/actors:
|
Entity/Actor |
Description |
|---|---|
|
the entity that is in control of the data exposed by the API, typically an end-user |
|
the mobile app, website, etc. that wants to access data on behalf of the Resource Owner |
|
|
|
the service/application/resource:
|

NOTE: This 1 of many Grant Flows (above portrays Implicit Flow of OAuth & OpenID Connect)