Resta saysOAuth 2.0 lets an app access a user’s data on another service without their password.
OAuth 2.0 is delegated authorization: "let this app read my Google contacts" without giving the app your Google password. The user authenticates with the provider, consents to specific scopes, and the app receives a token limited to those scopes. It's why "Sign in with Google" works. Several flows exist for different client types.
Power-ups you unlock
Delegated access without sharing passwords
User consents to specific scopes
App gets a scoped token from the provider
Powers "Sign in with X"
The 401 Bandit attacks — common mistakes
Confusing OAuth (authorization) with login alone
Requesting more scopes than needed
Picking the wrong flow for the client type
Boss battleExplain what "Sign in with Google" delegates and what it doesn’t.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>app → "read your contacts?" → you consent at Google
Google → app gets a token scoped to contacts
(app never sees your Google password)</pre></body></html>