OAuth 2.0

Authorisation framework (RFC 6749) that lets a user grant an application limited access to their resources on another service through access tokens, without sharing their password.

OAuth 2.0, defined in RFC 6749, is a framework for delegated authorisation. It lets a user allow an application to act on their behalf at another service without giving that application the user’s password. RFC 6749 names four roles: the resource owner (usually the user), the OAuth client (the application), the authorization server that issues tokens, and the resource server that holds the data. The client obtains an access token through a grant type and presents it to the resource server; the token commonly carries a limited scope and lifetime, and a refresh token can obtain a new one.

OAuth 2.0 is not by itself an authentication protocol. An access token says the client may do something, not who the user is or whether they are present, which is why OpenID Connect adds an identity layer on top of it. Access tokens are commonly bearer tokens (RFC 6750), so a stolen token can be used by whoever holds it. PKCE (RFC 7636) binds an authorization code to the client that requested it.

Exam relevance: questions in this area tend to turn on the difference between authorisation and authentication. A scenario about granting an app access to data without handing over a password points to OAuth; one about logging the user in points to OpenID Connect or SAML.