Glossary

OAuth

Also known as: oauth2, oauth-2.0, oauth-2.1, openid-connect, oidc
TechSecurityAuth

Definition

The IETF's delegated-authorization framework (OAuth 2.0, RFC 6749; 2.1 in draft): a user grants an application limited access to their account at another service without handing over a password, and the application receives a scoped, expiring access token to act with

Authorization, not authentication — OAuth says what an app may do, not who the user is. OpenID Connect is the thin identity layer on top that adds an ID token and a userinfo endpoint, and it is what 'Sign in with Google / GitHub / Apple' actually runs. The authorization-code flow with PKCE is the one to use from a browser or a native app; the implicit flow is retired. The tokens are the whole security surface: short-lived access tokens, refresh tokens kept server-side, scopes as narrow as the feature needs. Better Auth handles the GitHub flow for this site.

Tech

The valet key, in the original metaphor: it starts the car and opens the door, but not the trunk or the glove box, and it can be taken back without changing the locks. Every scope on a consent screen is one thing the key will open.

Related Terms

  • a: Appearance
  • ?: Keyboard shortcuts