SECURITY / A CONCEPT NOTE
OAuth 2.0
how apps get limited access to your data without your password
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A protocol where a user authorizes a third-party app (client) to access their data on another service (resource server). Instead of sharing a password, the client gets an access token — scoped, time-limited, and revocable. The authorization code flow is the gold standard for web apps.
02 / FOLLOW THE MECHANISM
How the authorization code flow works
User
clicks 'Sign in with Google' on a website (the client).
Client
redirects the user to Google's authorization endpoint with
client_id,redirect_uri, andscope.User
authenticates with Google and clicks 'Allow'. Google redirects back with a short-lived
authorization_code.Client
exchanges the code +
client_secretfor anaccess_tokenand optionally arefresh_tokenat Google's token endpoint.Client
uses the access_token in the
Authorization: Bearerheader to call Google APIs on behalf of the user.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
call an API with an OAuth2 token
curl -H "Authorization: Bearer $TOKEN" https://api.example.com/userexchange code for a token
curl -d "grant_type=authorization_code&code=..." https://auth.example.com/tokenThe ellipsis omits required code or values. This sketch is not runnable as written.
05 / CHECK YOURSELF
Could you explain OAuth 2.0 to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityZero Trustnever trust, always verify — no implicit access based on network location