Skip to main content
Book 07 · SecurityPage 22 of 50

OAuth

Pronunciation
OH-awth
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/oauth

In short

OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.

What is OAuth?

OAuth solves a common problem: an app, such as a scheduling tool, needs access to data held by another service, such as your calendar account, but you should not hand over your password. With OAuth, you log in directly with the service that holds your data, approve specific permissions called scopes, and the app receives an access token limited to those permissions.

The version in use is OAuth 2.0, and OAuth 2.1 consolidates its current best practices. The recommended flow for web and mobile apps is the authorization code flow with PKCE: the app redirects you to the authorization server, you log in and consent, the server redirects back with a short-lived code, and the app exchanges that code for an access token, often with a refresh token. The app then sends the access token to the API, which checks it before returning data.

A hotel key card is a good analogy. Reception, the authorization server, checks your identity once and gives you a card that opens only certain doors for a limited time; the doors, like the API, just check the card and never need to see your ID again.

OAuth is about authorization, meaning what an app is allowed to do, not authentication, meaning who the user is. Social login buttons, which let you sign in with an account you already have elsewhere, usually rely on OpenID Connect (OIDC), a layer on top of OAuth 2.0 that adds an ID token describing the user. Using OAuth safely means using PKCE, matching redirect URLs exactly, checking the state value, requesting only the scopes you need, and keeping tokens out of URLs and logs.

At a glance

The OAuth authorization code flow: the app redirects the user to the authorization server, the user logs in and approves scopes, the server redirects back with a short-lived code, the app exchanges the code for an access token, and then calls the API with that token.UserAppAPIAuthorizationserverredirect to log inlog in + approve scopesredirect back with a codeexchange code for a tokenaccess tokenAPI call + access tokendata
The app never sees the password: it gets a code through the browser, swaps it for a limited access token, and shows only that token to the API.

Key takeaways

  • OAuth lets apps access resources without collecting users' passwords.
  • Users approve limited permissions called scopes.
  • Apps receive access tokens, usually short-lived, instead of credentials.
  • The authorization code flow with PKCE is the recommended flow.
  • OpenID Connect adds login (authentication) on top of OAuth.

Example

Starting the authorization code flowjavascript
// Send the user to the authorization server to log in and consent
const params = new URLSearchParams({
  response_type: "code",            // ask for an authorization code
  client_id: "my-calendar-app",
  redirect_uri: "https://app.example.com/callback",
  scope: "calendar.read",           // only the permission that is needed
  state: savedState,                // random value, checked on return
  code_challenge: pkceChallenge,    // PKCE: protects the returned code
  code_challenge_method: "S256",
});

window.location.href = `https://auth.example.com/authorize?${params}`;

// Later, the app exchanges the returned ?code=... for an access token

Readers ask

What is the difference between OAuth and OpenID Connect?

OAuth 2.0 is for authorization: it gives an app an access token to call an API. OpenID Connect is built on top of OAuth and adds authentication, giving the app an ID token that says who the user is.

Is OAuth the same as JWT?

No. OAuth is a protocol that describes how apps obtain and use tokens, while JWT is a token format. Many OAuth servers issue access tokens as JWTs, but OAuth does not require it.

What is PKCE?

PKCE, short for Proof Key for Code Exchange, adds a one-time secret to the authorization code flow so a stolen code cannot be exchanged for a token by someone else. It is recommended for all OAuth clients, including web and mobile apps.

Often compared

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings