An open standard for delegated authorisation that allows a user to grant a third-party application limited access to a protected resource on behalf of a resource owner, using scoped, revocable access tokens rather than sharing credentials.
Semantic Classification
Content
- OAuth is an authorisation framework that enables an application to obtain limited access to a user’s resources held by another service, using access tokens rather than the user’s password. The user authorises the access through a consent step.
- By separating authentication from authorisation and issuing scoped, revocable tokens, OAuth reduces the exposure of credentials. The widely deployed OAuth 2.0 specification defines several grant types suited to different application architectures.