A client requests defined scopes and receives an access token after the resource owner or an authorized policy approves the grant. The resource server validates the token before serving protected operations. Different grant flows address interactive users, devices, and service-to-service access.