# OAuth

> The authorization protocol behind 'Sign in with Google' — lets a service act on your behalf with a scoped token instead of your password.

Before OAuth, giving a third-party app access meant handing over your password and hoping. OAuth turned it into a delegation: you authenticate at the provider, approve specific scopes ('read your calendar', not 'everything'), and the app receives a token that does exactly that much and no more.

The parts people confuse: OAuth is authorization (what you may do), OpenID Connect is the thin layer on top that adds authentication (who you are). The redirect dance looks complicated because it is — every step exists to stop a specific attack, from stolen codes to mixed-up clients.

## Related terms

- https://dfieldsolutions.com/en/glossary/jwt.md
- https://dfieldsolutions.com/en/glossary/mfa.md
- https://dfieldsolutions.com/en/glossary/least-privilege.md

---

Source: https://dfieldsolutions.com/en/glossary/oauth
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
