Lesson 15 / 24

OAuth 2.0 at a Glance

Delegated access without ever sharing a password.

Delegation, not identity

OAuth 2.0 lets a user grant a third-party app limited access to their data on another service — without ever handing over their password. The app receives a short-lived access token scoped to specific permissions.

The hotel key card

You don't hand the valet your house keys — the hotel gives you a key card that opens only your room, only for your stay. An OAuth access token is that key card: scoped and time-limited, revocable without changing your "real" password.

The main players

Resource owner (the user), client (the app requesting access), authorization server (issues tokens after login/consent), resource server (your API, which checks the token on each request).

Don't roll your own

OAuth 2.0 has several flows (authorization code, client credentials, etc.) with subtle security pitfalls. Use a maintained library or identity provider rather than implementing the flow from scratch.