AiVibe

Cybersecurity & Compliance

OAuth 2.0

An authorisation framework, defined in IETF RFC 6749, that lets an application obtain limited, delegated access to a user's resources on another service through access tokens, without handling the user's password.

OAuth 2.0 defines four roles: the resource owner, usually the user; the client application; the authorisation server, which authenticates the user and issues tokens; and the resource server, which hosts the protected APIs. In the authorisation code flow, the client redirects the user to the authorisation server, receives a short-lived code after the user consents and exchanges it for an access token, often with a refresh token. Scopes limit what each token permits.

OAuth underpins delegated access for third-party integrations, mobile apps and single-page applications, and the client credentials grant supports machine-to-machine API access. OpenID Connect adds an identity layer on top of OAuth 2.0, issuing ID tokens so that applications can authenticate users, a task OAuth alone was not designed for, and it is widely used for social and enterprise single sign-on.

Implementation mistakes are a common source of vulnerabilities, including weak redirect URI validation, open redirects, missing or unchecked state parameters and tokens leaked in URLs or logs. The IETF's security best current practice for OAuth 2.0 recommends the authorisation code flow with PKCE, avoiding the implicit and resource owner password grants, and keeping access tokens short-lived and narrowly scoped.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Ask AiMuruga can explain OAuth 2.0 for your plant, product or security programme, and draw how it fits.