SECURITY / A CONCEPT NOTE

OAuth 2.0

how apps get limited access to your data without your password

~90 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A protocol where a user authorizes a third-party app (client) to access their data on another service (resource server). Instead of sharing a password, the client gets an access token — scoped, time-limited, and revocable. The authorization code flow is the gold standard for web apps.

02 / FOLLOW THE MECHANISM

How the authorization code flow works

  1. User

    clicks 'Sign in with Google' on a website (the client).

  2. Client

    redirects the user to Google's authorization endpoint with client_id, redirect_uri, and scope.

  3. User

    authenticates with Google and clicks 'Allow'. Google redirects back with a short-lived authorization_code.

  4. Client

    exchanges the code + client_secret for an access_token and optionally a refresh_token at Google's token endpoint.

  5. Client

    uses the access_token in the Authorization: Bearer header to call Google APIs on behalf of the user.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

call an API with an OAuth2 token

curl -H "Authorization: Bearer $TOKEN" https://api.example.com/user

EXAMPLE 02 · INCOMPLETE SKETCH

exchange code for a token

curl -d "grant_type=authorization_code&code=..." https://auth.example.com/token

The ellipsis omits required code or values. This sketch is not runnable as written.

Explore command anatomy in the CLI lab