Question

What is OAuth actually for?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Delegated authorisation — letting an application act on a user's behalf against another service, without the user handing over their password. It is frequently described as a login mechanism, which is a misunderstanding that causes real security problems.

The problem it solves. Before it, an application that needed your data from another service asked for your username and password for that service. That gave it unlimited, permanent access to everything, indistinguishable from you. OAuth replaces this with scoped, revocable, time-limited tokens.

The roles: the resource owner (the user), the client (the application requesting access), the authorisation server (which authenticates the user and issues tokens), and the resource server (which holds the data).

The flow, in outline. The client redirects the user to the authorisation server; the user authenticates there, not with the client, and consents to specific scopes; the authorisation server returns a short-lived code to the client; the client exchanges that code, plus its own credentials, for an access token. The client never sees the password.

Why the code exchange exists rather than returning the token directly: it keeps the token out of URLs, browser history and referrer headers.

The crucial distinction: OAuth is authorisation, not authentication. An access token proves the client may access a resource — it does not prove who the user is, and using one as a login signal was the source of well-documented vulnerabilities. OpenID Connect is the layer built on top of OAuth that does authentication properly, adding an ID token with verified identity claims.

What to use now:

Authorisation code flow with PKCE, for essentially everything including mobile and single-page applications. The implicit flow is deprecated.

Client credentials flow for machine-to-machine, where no user is involved.

What to get right: validate the state parameter to prevent CSRF, register exact redirect URIs, request the narrowest scopes, and never accept tokens from an untrusted source without verifying them with the issuer.

Related Questions