OAuth 2.0
An authorisation framework, defined in IETF RFC 6749, that lets an application obtain limited, delegated access to a user's resources on another service through access tokens, without handling the user's password.
OAuth 2.0 defines four roles: the resource owner, usually the user; the client application; the authorisation server, which authenticates the user and issues tokens; and the resource server, which hosts the protected APIs. In the authorisation code flow, the client redirects the user to the authorisation server, receives a short-lived code after the user consents and exchanges it for an access token, often with a refresh token. Scopes limit what each token permits.
OAuth underpins delegated access for third-party integrations, mobile apps and single-page applications, and the client credentials grant supports machine-to-machine API access. OpenID Connect adds an identity layer on top of OAuth 2.0, issuing ID tokens so that applications can authenticate users, a task OAuth alone was not designed for, and it is widely used for social and enterprise single sign-on.
Implementation mistakes are a common source of vulnerabilities, including weak redirect URI validation, open redirects, missing or unchecked state parameters and tokens leaked in URLs or logs. The IETF's security best current practice for OAuth 2.0 recommends the authorisation code flow with PKCE, avoiding the implicit and resource owner password grants, and keeping access tokens short-lived and narrowly scoped.
Key points
- Provides delegated authorisation through scoped access tokens.
- Defined in RFC 6749; OpenID Connect adds authentication on top.
- The authorisation code flow with PKCE is current best practice.
- Strict redirect URI validation and short-lived tokens prevent common attacks.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.