Before OAuth, giving a third-party app access meant handing over your password and hoping. OAuth turned it into a delegation: you authenticate at the provider, approve specific scopes ('read your calendar', not 'everything'), and the app receives a token that does exactly that much and no more.
The parts people confuse: OAuth is authorization (what you may do), OpenID Connect is the thin layer on top that adds authentication (who you are). The redirect dance looks complicated because it is — every step exists to stop a specific attack, from stolen codes to mixed-up clients.
Related terms
JWT
JSON Web Token — a signed, self-contained credential a server can verify without a database lookup; the standard way APIs say 'this request is you'.
MFA / 2FA
Multi-factor authentication — proving identity with something you know plus something you have, so a leaked password alone cannot log in.
Least privilege
Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.
The bench this belongs to
Full-stackIf you can describe it, we can build it. React and Next.js on the front, Python or Node behind, Postgres underneath, shipped to somewhere you can afford to run.
