OAuth
OAuth is an authorization standard that lets an app get limited access to your account on another service, with your approval and without learning your password. Instead of the password, the app receives a time-limited access token. You can take that permission back at any time.
What is OAuth?
OAuth is the standard way to let software reach one of your accounts without handing over your password. The version in use today is OAuth 2.0. In short, it delegates permission: it lets you say "this app may read my calendar but not my email".
Here is an everyday case. You want your booking system to add appointments to your Google Calendar. The old way was to type your Google password into the booking system, which could then reach everything. With OAuth, the booking system sends you to Google's own sign-in page. Google asks whether the app may view and edit your calendar. You approve, and the booking system receives a time-limited token that works only for the calendar. Your password is never shared.
Why does it matter?
No shared password means less risk of a leak. Permissions stay narrow and can be revoked with one click in your account settings. "Sign in with Google" buttons usually run on OpenID Connect, which is built on OAuth 2.0. Most accounting, marketplace and payment services require OAuth for API access, and we set these connections up in our integrations work. Two-factor authentication should be switched on as well.
Frequently asked questions
Is OAuth a login method?
At its core it is an authorization standard: it grants an app permission to reach certain data. Identity is handled by OpenID Connect, which is built on top of it. "Sign in with Google" buttons usually use both.
How do I revoke a permission I gave?
The service you granted it on has a connected apps section in its account settings. Remove the app there and its token stops working.
Does the app see my password with OAuth?
No. You type your password only on the sign-in page of the service that owns the account. The app receives a time-limited access token instead.
Sources
- 01 OAuth 2.0 · oauth.net