EMZETT.
Login

OAuth

In short: OAuth (today usually OAuth 2.0) is a standard that lets an app access a user’s data at another service on the user’s behalf without receiving the password.

In more detail: Typical example: “Sign in with Discord” or “Sign in with Google”. The site sends you to the provider. There you sign in and confirm what the app may see. The app then only receives a token, never your password.

In Depth

Parties

  • Resource owner: the user.
  • Client: the app that wants access.
  • Authorisation server: the provider where you sign in and consent.
  • Resource server: the API holding the data.

Flow (authorisation code flow)

  1. The app sends the user to the provider, with the requested scopes (permissions, e.g. “read email”).
  2. The user signs in and consents.
  3. The provider sends a short-lived code back to the app.
  4. The app exchanges the code on its server for an access token (and possibly a refresh token).
  5. With the access token it calls the API.

Good to know

  • OAuth handles access (authorisation). Login (“who are you?”) is added on top by OpenID Connect.
  • Tokens are like keys: protect them well, keep them short-lived, send them only over HTTPS.
  • The state parameter and PKCE protect against forgery and intercepted codes (security in web development).
  • Access can be revoked at the provider at any time.

See also: 2FA, cookies, session