An open standard for delegated authorisation that allows a user to grant a third-party application limited access to a protected resource on behalf of a resource owner, using scoped, revocable access tokens rather than sharing credentials.

Semantic Classification

Content

  • OAuth is an authorisation framework that enables an application to obtain limited access to a user’s resources held by another service, using access tokens rather than the user’s password. The user authorises the access through a consent step.
  • By separating authentication from authorisation and issuing scoped, revocable tokens, OAuth reduces the exposure of credentials. The widely deployed OAuth 2.0 specification defines several grant types suited to different application architectures.

Provenance