1) Authorization code grant type Figure 1 Can use to obtain both access token and refresh tokens. The flow of authorization code grant type is as follows. When user authorize the third party app to access data, the app request for authorization. Then the authorization server authenticates the resource owner. The access token is sent to client application as the response. The client app request for the access token, using the authorization code. The client app gets receive the access token as the response. 2) Implicit grant type Figure 2 Client is not authenticated in implicit grant type, as in authorization code grant type...