OAuth
- Pronunciation
- OH-awth
In short
OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
What is OAuth?
OAuth solves a common problem: an app, such as a scheduling tool, needs access to data held by another service, such as your calendar account, but you should not hand over your password. With OAuth, you log in directly with the service that holds your data, approve specific permissions called scopes, and the app receives an access token limited to those permissions.
The version in use is OAuth 2.0, and OAuth 2.1 consolidates its current best practices. The recommended flow for web and mobile apps is the authorization code flow with PKCE: the app redirects you to the authorization server, you log in and consent, the server redirects back with a short-lived code, and the app exchanges that code for an access token, often with a refresh token. The app then sends the access token to the API, which checks it before returning data.
A hotel key card is a good analogy. Reception, the authorization server, checks your identity once and gives you a card that opens only certain doors for a limited time; the doors, like the API, just check the card and never need to see your ID again.
OAuth is about authorization, meaning what an app is allowed to do, not authentication, meaning who the user is. Social login buttons, which let you sign in with an account you already have elsewhere, usually rely on OpenID Connect (OIDC), a layer on top of OAuth 2.0 that adds an ID token describing the user. Using OAuth safely means using PKCE, matching redirect URLs exactly, checking the state value, requesting only the scopes you need, and keeping tokens out of URLs and logs.
At a glance
Key takeaways
- OAuth lets apps access resources without collecting users' passwords.
- Users approve limited permissions called scopes.
- Apps receive access tokens, usually short-lived, instead of credentials.
- The authorization code flow with PKCE is the recommended flow.
- OpenID Connect adds login (authentication) on top of OAuth.
Example
// Send the user to the authorization server to log in and consent
const params = new URLSearchParams({
response_type: "code", // ask for an authorization code
client_id: "my-calendar-app",
redirect_uri: "https://app.example.com/callback",
scope: "calendar.read", // only the permission that is needed
state: savedState, // random value, checked on return
code_challenge: pkceChallenge, // PKCE: protects the returned code
code_challenge_method: "S256",
});
window.location.href = `https://auth.example.com/authorize?${params}`;
// Later, the app exchanges the returned ?code=... for an access tokenReaders ask
What is the difference between OAuth and OpenID Connect?
OAuth 2.0 is for authorization: it gives an app an access token to call an API. OpenID Connect is built on top of OAuth and adds authentication, giving the app an ID token that says who the user is.
Is OAuth the same as JWT?
No. OAuth is a protocol that describes how apps obtain and use tokens, while JWT is a token format. Many OAuth servers issue access tokens as JWTs, but OAuth does not require it.
What is PKCE?
PKCE, short for Proof Key for Code Exchange, adds a one-time secret to the authorization code flow so a stolen code cannot be exchanged for a token by someone else. It is recommended for all OAuth clients, including web and mobile apps.
Often compared
- OAuth vs SSOOAuth lets an app reach a user's data on another service without their password, while SSO is one login for many apps, built on SAML or OpenID Connect.
- OAuth vs OpenID ConnectOAuth 2.0 lets an app access an API for a user with an access token; OpenID Connect adds an identity layer that says who the user is with a signed ID token.
- JWT vs OAuthOAuth is a framework for giving an app limited access to user data; a JWT is a token format. They aren't rivals: OAuth often issues JWT access tokens.
See also
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- CSRFSecurity, p. 8CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- REST APIBackend & APIs, p. 38A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- OpenID ConnectSecurity, p. 23OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
- Refresh TokenSecurity, p. 33A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
Sources
Spotted a mistake or something missing on this page?Suggest an edit