What is OAuth2? A Real World Example.


What is OAuth2? It can seem quite complicated, but it doesn’t have to be. Before OAuth2, when you needed to give software services access to your account, you had to give that service your username and password. This meant there was no way to tell whether it was you or the agent accessing your data as a third party doing so on your behalf. That agent had access to everything in that account and you’d have to change the account password when you decided to cancel that service. Just like when you give somebody the physical key to your apartment, that person then has complete access to everything on the inside. You’d have to change the locks if you decided you no longer wanted to allow that access.

How does it work?

With OAuth2, things are different. For instance, rather than giving away your usernames and passwords, they are replaced with “access tokens.” This changes the way third parties access your account. Read about that and more in this forum blog post by ForgeRock's Jake Feasel, in which he explains the need OAuth2 was created to fill, the basic way it works, and what that has to do with the person you hire to walk your dog.

Check out more about the ForgeRock Identity Platform here.


Who Is Greta Sohn?

Who’s Greta? Greta is our Content Marketing Specialist. She graduated from University of Washington (go Dawgs!) with a business degree and has worked in Bay Area tech over the past 2 years. She loves traveling, spending time with her family dog, and her favorite San Francisco landmark is Sutro Tower. You'll most likely find Greta in the Mission District with cheese in one hand and petting someone else's dog with the other.

Recent Posts:

API Security: Awareness and Moderation are Key

A Buddhist approach towards addressing the uncertainty of API Security

2500 years ago, light was shed on the philosophy of moderation. It was the key to health and happiness as taught in Buddhism. Similarly, this approach also applies to our reckless world of technology.

ForgeRock Identity Cloud: Early Access Program

We started a journey last December with the release of the ForgeRock Identity Platform 6.5, which helps customers transition millions of users from on-premises to cloud-hosted services in minutes.

API Security: Applying the Separation of Concerns Design Principle

You may have been wondering what a clever person like Edsger Dijkstra would have considered the best way to approach API security. You aren't the only one.