Glossary Security

OAuth

OAuth is a standard that lets one app act on your behalf at another service, such as "Sign in with Google", without ever seeing your password.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

You approve the request at the service you already use, which then gives the app a limited, revocable access token (often a JWT) with specific permissions, called scopes. OAuth is about authorisation; the OpenID Connect layer on top adds proof of who you are. Apps should request only the scopes they need.

See also

  • Glossary JWT
    A JWT (JSON Web Token) is a compact, signed token made of three Base64URL parts that carries claims such as who a user is and when the.
  • Glossary API
    An API (application programming interface) is a defined way for one piece of software to ask another to do something or share data.
  • Glossary Multi-factor authentication (MFA)
    Multi-factor authentication (MFA) requires two or more kinds of proof to sign in.
AdSense Placeholder
Slot: footer_leaderboard