top of page

Welcome
to NumpyNinja Blogs

NumpyNinja: Blogs. Demystifying Tech,

One Blog at a Time.
Millions of views. 

Exploring OAuth: How Secure Authorization Works

Apr 30, 2025
5 min read
"The Backbone of Secure Communication"

A proper understanding of OAuth starts with understanding the basics of Authentication and Authorization, the two core concepts that OAuth is built upon. Before jumping into OAuth, let's quickly explore what these terms mean.


What is Authentication?

Authentication is the process of verifying a user's identity before granting access. In simple terms, it is the process of verifying who you are.

For example, if you are walking up to the front desk at a hotel. The receptionist asks for your ID to confirm your identity before handing over the key. That's Authentication in real life.

In the context of software and APIs, Authentication involves:

  • Entering a Username and Password

  • Using Biometric data (Face ID or fingerprint)

  • Providing an API key or access Token

  • Logging in with a third-party service (Google, Facebook)

If the authentication fails, the request will be denied immediately.


What is Authorization?

Authorization is the process of defining what the authenticated user is allowed to access. It determines the access level and privileges for an authenticated user.

For example, after the receptionist confirms your identity, they will check the booking details to see which room you are allowed in and what amenities you have access to.

In the context of APIs, Authorization involves:

  • What actions and resources do the authenticated user or app have permission for?

  • What data or endpoints a user can access?

  • What is the permission level of the user, such as read, write, and delete?

  • Enforcing role-based access control like admin, user, and guest.

  • Applying scopes to limit access.

Even if a user is authenticated, a user might not have authorization to access all the parts of the API. Now, we know what Authentication and Authorization are. Let's see about OAuth.


What is OAuth?

OAuth stands for Open Authorization, a widely used authorization framework that allows one app to access data from another app without sharing the full login credentials. It was developed to create a more secure method for third-party authorization. This approach enhances security by granting specific permissions through tokens rather than exposing sensitive user information.


 How does OAuth work?

OAuth works by exchanging Access Tokens. An Access Token is an electronic key that contains information about the user and their access level. It also includes specific rules like, when the application can use the token and the expiration detail of the token.

 When we use “Login with Google” or “Login with Facebook” on a website or app to log in without explicitly signing up with a username and password, the OIDC (OpenID Connect) and OAuth takes care of the authentication and authorization in the background and provides necessary access to the user. OIDC is built on top of OAuth that provides authentication.

 

Real-Time Use Case:

Imagine you are on Airbnb trying to rent one single floor from the whole house, so the host will give the keys just for that floor you rented but not for the other rooms in the house. In the context of OAuth, Google is the whole house which contains a lot of information about the user and the keys for your floor represent the returned Access Token. With that Access Token, you can only get the information that you actually requested such as the user’s email address, and profile picture but not more than that.


For example, if we log into any app like “Dropbox” using Google,

1.      User Clicks Continue with Google

2.      Dropbox doesn’t ask for email or password directly. It redirects to Google’s Authorization server.        




     

3.      Google Asks for the permission after selecting the account to login. It shows the prompt like “Google will

share your name, email, and profile picture with Dropbox as below




 


4.     You Click Continue

5.      At this step, Google does not give the password. It gives Dropbox a temporary authorization code, which

acts as a permission slip.

6.      The app uses that token to access the files without even seeing and sharing the password.

 

Key OAuth Components:

OAuth works through a three-party authorization process involving the user, client application, and authorization server. In addition to the three main parties involved, OAuth also defines several other key components that are essential for secure authorization.

Term

Description

Client Application

The app that needs access (Example: Dropbox)

Resource Owner

The user

Authorization Server

The service that verifies the user's identity and issues an access token (Example: Google)

Resource Server

Hosts the protected resources (Google Drive API)

Access Token

A temporary key (Dropbox uses that key to access the drive)


Why OAuth is Important:

  •  Revocable Access - OAuth Access Token can be revoked at any time, providing users with control over application access.

  •  No Permanent Credential Sharing - OAuth ensures that no permanent credentials are shared.

  • Encrypted Communication - OAuth uses encrypted communication channels to protect sensitive data during the authorization process.

  • Cross Platform - OAuth works across web applications, mobile apps, and smart devices.

  • Separation of Responsibilities - OAuth separates Authentication and Authorization which allows better security architecture, clearer access control, and flexible integration.

  • Token-Based System - OAuth uses Access Tokens instead of explicitly giving a username and password.


Versions of OAuth:

OAuth1.0

  • The Original version of OAuth is OAuth1.0

  • OAuth1.0 uses signed tokens, and every API request must be signed using cryptographic methods. This involves generating the signatures using a secret key, which is complex to implement, test, and debug.

  • OAuth1.0 does not rely on HTTPS for security as it uses cryptographic signatures that ensure the integrity and authenticity of requests.

  • Tokens used in OAuth1.0 are long-lived which may lead to security risks if tokens are not properly managed.

  • OAuth1.0 was developed only for websites.

  • It is deprecated and replaced by OAuth2.0.

OAuth2.0

  • OAuth2.0 is not just a version upgrade; it is a complete redesign of OAuth1.0 which focuses on ease of use, scalability, and supporting modern apps.

  • OAuth2.0 trusts Https to handle security, so complex cryptographic signatures are not required.

  • OAuth2.0 uses short-lived Access Tokens which ensures security by enforcing regular token renewal for continued access.

  • One of the key advantages of OAuth2.0 over OAuth1.0 is that it supports the Refresh Tokens mechanism.

  • A Refresh Token is like a back-up key that allows the app to ask for a new access token when the old one expires without the need to log in again.

  • Access Tokens and Refresh Tokens are simpler and easier to implement and integrate.

OAuth2.1

  • As I write this blog, OAuth 2.1 is an upcoming draft specification that consolidates the most commonly used features of OAuth2.0. It has some changes to improve security by requiring PKCE (Proof Key for Code Exchange) for all apps and enforcing stricter rules for token handling.

  • PKCE (Proof Key for Code Exchange) is an extra security step used during the OAuth login process.


Conclusion:

As technology keeps evolving, the way we handle authentication and authorization is also changing. There is a growing focus on

  • User Privacy

  • Data Protection

  • Secure ways for apps to access data without explicitly giving passwords

Protocols like OAuth will continue to grow and improve, offering more secure and user-friendly ways to manage and share data.

 
 

+1 (302) 200-8320

NumPy_Ninja_Logo (1).png

Numpy Ninja Inc. 8 The Grn Ste A Dover, DE 19901

© Copyright 2025 by Numpy Ninja Inc.

  • Twitter
  • LinkedIn
bottom of page