Salesforce Certified Identity and Access Management Practice

Disable ads (and more) with a membership for a one time $4.99 payment

Study for the Salesforce Certified Identity and Access Management Exam. Utilize flashcards, multiple choice questions, and comprehensive explanations to prepare thoroughly. Get ready to ace your exam!

Practice this question and more.


How does the user-agent flow transport the access token?

  1. Via email

  2. By SMS

  3. Through server-to-server communication

  4. The access token is received as an HTTP redirection

The correct answer is: The access token is received as an HTTP redirection

The user-agent flow, often used for obtaining access tokens in scenarios involving user login via a web browser, utilizes HTTP redirection to convey the access token. When the user successfully authenticates through the identity provider, the provider redirects the user-agent (the web browser) back to the application with the access token included in the URL fragment or query parameters. This method is efficient because it leverages the existing web technologies of URLs and redirects, enabling a seamless user experience. Additionally, this allows the token to be securely passed back to the client application without the need for alternate transport mechanisms like email, SMS, or server-to-server communication, which are not suitable for direct user interaction in the context of authentication flows.