Skip to main content
ProtocolCurrent

OAuth 2.0

Also known as: OAuth

Following adds this technology to your private workspace so related learning is easier to organise and revisit.

Technology explained

What is OAuth 2.0?

OAuth 2.0 is an authorisation framework for granting applications limited access to resources without sharing a user's password. This profile connects the concept to KBY's practical engineering guidance.

An authorisation server issues scoped access tokens to clients through flows designed for different trust and interaction models. OAuth does not itself define user authentication; secure deployments require exact redirect handling, sender constraints where appropriate and modern proof mechanisms such as PKCE.

Primary purpose

Delegate scoped API access between users, clients and resource servers.

Typical environments
Web ServicesMobile Apps
Typical use cases
  • Delegated API access
  • Third-party application integration
  • Mobile app authorization
Technology map

Explore related technologies

Related technologies

Connected knowledge

1 resource for OAuth 2.0

Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.

Technology journey

Learn and operate with OAuth 2.0

Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.

Lexicon Definitions(1)

Start here: understand the core vocabulary.