Resource owner (OAuth)

The OAuth 2.0 role for the entity able to grant access to a protected resource. When that entity is a person, RFC 6749 calls it the end-user.

The resource owner is one of the four roles in the OAuth 2.0 framework, RFC 6749: the entity capable of granting access to a protected resource. When the resource owner is a person, the RFC calls them the end-user. In the common case, a person using a third-party application is asked by the authorization server whether that application may act on their data, and their approval on the consent screen is the authorisation that the resulting OAuth grant represents.

In the authorization code flow, the resource owner authenticates only with the authorization server, so the OAuth client does not handle their credentials (RFC 6749 section 1.3.1). The client receives an access token limited to the scope the owner approved and presents it to the resource server. The roles are easy to blur: the resource owner decides, the resource server holds the data, and the client asks. The OAuth role is also narrower than the governance data owner, who is accountable for classifying and protecting a data set.

Exam relevance: a scenario is likely to describe a user approving an application’s request to reach their data and ask which role that user plays. Candidates are expected to name the resource owner, and to remember that OAuth delegates authorisation rather than authenticating the user, the layer OpenID Connect adds.