Authorization server (OAuth)

The OAuth 2.0 role that authenticates the resource owner, obtains their authorisation and issues access tokens (and often refresh tokens) to the client.

The authorization server is one of the four roles defined in RFC 6749, the OAuth 2.0 framework. It authenticates the resource owner, obtains their consent, and issues access tokens to the OAuth client, commonly with refresh tokens as well. The other three roles are the resource owner, the client and the resource server that hosts the protected data. RFC 6749 allows the authorization server and the resource server to be the same system or separate ones, and one authorization server can issue tokens accepted by many resource servers.

Candidates commonly blur it with the resource server. The authorization server issues tokens; the resource server accepts them and serves the data. The authorization server is also where the client exchanges an authorisation code for tokens, which is the step that PKCE protects by binding the code to the client that asked for it. When OpenID Connect is layered on top, the same server acts as the OpenID provider and also issues an ID token, which makes it a form of identity provider.

Exam relevance: a scenario is likely to describe an OAuth flow and ask which role performs a step. Candidates are expected to place consent and token issuance with the authorization server, protected data with the resource server, and the request itself with the client.