DFIELDSOLUTIONS

Security

GlossaryOAuth

The authorization protocol behind 'Sign in with Google' — lets a service act on your behalf with a scoped token instead of your password.

Before OAuth, giving a third-party app access meant handing over your password and hoping. OAuth turned it into a delegation: you authenticate at the provider, approve specific scopes ('read your calendar', not 'everything'), and the app receives a token that does exactly that much and no more.

The parts people confuse: OAuth is authorization (what you may do), OpenID Connect is the thin layer on top that adds authentication (who you are). The redirect dance looks complicated because it is — every step exists to stop a specific attack, from stolen codes to mixed-up clients.

Related terms

The bench this belongs to

Full-stack

If you can describe it, we can build it. React and Next.js on the front, Python or Node behind, Postgres underneath, shipped to somewhere you can afford to run.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain