# OAuth

URL: https://softwaredictionary.org/terms/oauth
Category: Security
Last updated: 2026-09-29
Pronunciation: OH-awth

In short: OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.

## What is OAuth?

OAuth solves a common problem: an app, such as a scheduling tool, needs access to data held by another service, such as your calendar account, but you should not hand over your password. With OAuth, you log in directly with the service that holds your data, approve specific permissions called scopes, and the app receives an access token limited to those permissions.

The version in use is OAuth 2.0, and OAuth 2.1 consolidates its current best practices. The recommended flow for web and mobile apps is the authorization code flow with PKCE: the app redirects you to the authorization server, you log in and consent, the server redirects back with a short-lived code, and the app exchanges that code for an access token, often with a refresh token. The app then sends the access token to the API, which checks it before returning data.

A hotel key card is a good analogy. Reception, the authorization server, checks your identity once and gives you a card that opens only certain doors for a limited time; the doors, like the API, just check the card and never need to see your ID again.

OAuth is about authorization, meaning what an app is allowed to do, not authentication, meaning who the user is. Social login buttons, which let you sign in with an account you already have elsewhere, usually rely on OpenID Connect (OIDC), a layer on top of OAuth 2.0 that adds an ID token describing the user. Using OAuth safely means using PKCE, matching redirect URLs exactly, checking the `state` value, requesting only the scopes you need, and keeping tokens out of URLs and logs.

## Key takeaways

- OAuth lets apps access resources without collecting users' passwords.
- Users approve limited permissions called scopes.
- Apps receive access tokens, usually short-lived, instead of credentials.
- The authorization code flow with PKCE is the recommended flow.
- OpenID Connect adds login (authentication) on top of OAuth.

## Example: Starting the authorization code flow

```javascript
// Send the user to the authorization server to log in and consent
const params = new URLSearchParams({
  response_type: "code",            // ask for an authorization code
  client_id: "my-calendar-app",
  redirect_uri: "https://app.example.com/callback",
  scope: "calendar.read",           // only the permission that is needed
  state: savedState,                // random value, checked on return
  code_challenge: pkceChallenge,    // PKCE: protects the returned code
  code_challenge_method: "S256",
});

window.location.href = `https://auth.example.com/authorize?${params}`;

// Later, the app exchanges the returned ?code=... for an access token
```

## Frequently asked questions

**What is the difference between OAuth and OpenID Connect?**

OAuth 2.0 is for authorization: it gives an app an access token to call an API. OpenID Connect is built on top of OAuth and adds authentication, giving the app an ID token that says who the user is.

**Is OAuth the same as JWT?**

No. OAuth is a protocol that describes how apps obtain and use tokens, while JWT is a token format. Many OAuth servers issue access tokens as JWTs, but OAuth does not require it.

**What is PKCE?**

PKCE, short for Proof Key for Code Exchange, adds a one-time secret to the authorization code flow so a stolen code cannot be exchanged for a token by someone else. It is recommended for all OAuth clients, including web and mobile apps.

## Sources

- [RFC 6749: The OAuth 2.0 Authorization Framework](https://www.rfc-editor.org/rfc/rfc6749.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
