freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #35 of 45

oauth 2.0 · delegated access

RestaVSThe 401 Bandit
Resta saysOAuth 2.0 lets an app access a user’s data on another service without their password.

OAuth 2.0 is delegated authorization: "let this app read my Google contacts" without giving the app your Google password. The user authenticates with the provider, consents to specific scopes, and the app receives a token limited to those scopes. It's why "Sign in with Google" works. Several flows exist for different client types.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain what "Sign in with Google" delegates and what it doesn’t.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>app → "read your contacts?" → you consent at Google
Google → app gets a token scoped to contacts
(app never sees your Google password)</pre></body></html>
▶ Open the interactive comic issue
‹ Bearer Tokens · The StandardOauth · Authorization Code Flow ›