> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superoffice.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Which flow should you use?

> Authentication scenarios for various app types

The following table is meant to assist you in determining which OAuth/OpenID Connect flow is best suited for your application type.

<Warning>
  We recommend all interactive applications use Authorization Code flow with PKCE where appropriate. Implicit and Hybrid flow are not secure enough and should be avoided at all costs. Deprecated.
</Warning>

## Authentication scenarios for various app types

| App type               | Native/mobile app                               | Single-page app (SPA)        | Regular web app                                    | non-interactive backend / API             |
| ---------------------- | ----------------------------------------------- | ---------------------------- | -------------------------------------------------- | ----------------------------------------- |
| User context           | Interactive                                     | Interactive                  | Interactive                                        | Non-interactive                           |
| Environment            | Runs on device or OS                            | Runs in browser              | Runs on server                                     | Runs on server                            |
| Flow                   | [Native app flow][1]                            | [Implicit flow][2]           | [Authorization Code flow][3], with or without PKCE | [SuperOffice system user flow][4]         |
| Typical stack          | OS-specific                                     | JavaScript                   | .NET<br />PHP                                      | web service<br /> Windows service         |
| App identifiers (keys) | client ID                                       | client ID                    | client ID, client secret                           | client ID, client secret                  |
| Response tokens        | ID token<br />access token<br />(refresh token) | ID token<br />(access token) | ID token<br />access token<br />(refresh token)    | system user token<br />system user ticket |

*This overview has been simplified for the clarity of the presentation.*

[1]: ./sign-in-user/native-apps

[2]: ./sign-in-user/implicit-flow

[3]: ./sign-in-user/auth-code-flow

[4]: ./auth-application/index


## Related topics

- [Create a new flow](/en/marketing/flows/learn/create.md)
- [What API to use?](/en/developer-portal/getting-started/what-api-to-use.md)
- [Step settings](/en/marketing/flows/learn/step-settings.md)
- [Run, pause, and end flow](/en/marketing/flows/learn/run-pause-end.md)
- [Define flow actions](/en/marketing/flows/learn/define-flow-actions.md)
- [Analyze your flow results](/en/marketing/flows/learn/view-statistics.md)
