OAuth 2.0

E35337

OAuth 2.0 is an industry-standard authorization framework that enables applications to obtain limited access to user resources on HTTP services without exposing user credentials.

AI illustration

How this image was made

AI-generated illustration of OAuth 2.0

This AI-generated illustration was produced by black-forest-labs/FLUX.2-dev (1024x1024) from a prompt written by openai/gpt-oss-120b from the entity's label + description.

Prompt

Generate an image of OAuth 2.0 (OAuth 2.0 is an industry-standard authorization framework that enables applications to obtain limited access to user resources on HTTP services without exposing user credentials.)

All labels observed (26)

How this entity was disambiguated

Statements (47)

Predicate Object
instanceOf IETF standard ⓘ
authorization framework ⓘ
internet standard ⓘ
allows third-party applications to access APIs on behalf of users ⓘ
BearerTokenSpecifiedIn RFC 6750 ⓘ
category computer security protocol ⓘ
web authorization protocol ⓘ
definesEndpoint authorization endpoint ⓘ
redirection endpoint ⓘ
token endpoint ⓘ
definesGrantType authorization code grant ⓘ
client credentials grant ⓘ
implicit grant ⓘ
resource owner password credentials grant ⓘ
definesRole authorization server ⓘ
client ⓘ
resource owner ⓘ
resource server ⓘ
designedFor authorization ⓘ
enables delegated access to protected resources ⓘ
limited access without sharing user credentials ⓘ
influenced OpenID Connect ⓘ
isExtendedBy OpenID Connect Core ⓘ
linked to: OpenID Connect
isUsedBy Facebook APIs ⓘ
linked to: Facebook

GitHub APIs ⓘ
linked to: GitHub

Google APIs ⓘ
Microsoft APIs ⓘ
minimizes exposure of user credentials ⓘ
notDesignedFor authentication ⓘ
operatesOver HTTP ⓘ
publishedYear 2012 ⓘ
replaces OAuth 1.0 ⓘ
requires user authorization for client access ⓘ
securityDependsOn TLS ⓘ
separates resource server from authorization server ⓘ
standardizedBy Internet Engineering Task Force ⓘ
standardizedIn RFC 6749 ⓘ
RFC 6750 ⓘ
supports JavaScript applications ⓘ
extension grant types ⓘ
machine-to-machine applications ⓘ
native applications ⓘ
scopes for fine-grained access control ⓘ
web applications ⓘ
tokenTypeDefinedIn Bearer token ⓘ
uses access tokens ⓘ
refresh tokens ⓘ

How these facts were elicited

Referenced by (69)

Full triples — surface form annotated when it differs from this entity's canonical label.

Google Play Games → loginMethod → Google account OAuth ⓘ
linked to: OAuth 2.0
Oracle Access Manager → supportsProtocol → OAuth ⓘ
linked to: OAuth 2.0
Thunderbird → supportsStandard → OAuth2 ⓘ
linked to: OAuth 2.0
RFC 6749 → title → The OAuth 2.0 Authorization Framework ⓘ
linked to: OAuth 2.0
RFC 6749 → defines → OAuth 2.0 authorization framework ⓘ
linked to: OAuth 2.0
RFC 6749 → relatedTo → OAuth 2.0 ⓘ
OAuth 1.0 → predecessorOf → OAuth 2.0 ⓘ
OAuth 1.0 → supersededBy → OAuth 2.0 ⓘ
OAuth 1.0 → relatedTo → OAuth 2.0 ⓘ
OpenID Connect → builtOn → OAuth 2.0 ⓘ
OpenID Connect → relatedStandard → OAuth 2.0 ⓘ
Jira → supportsAuthentication → OAuth ⓘ
linked to: OAuth 2.0
RFC 6750 → protocolFramework → OAuth 2.0 Authorization Framework ⓘ
linked to: OAuth 2.0
JSON Web Token → commonlyUsedWith → OAuth 2.0 ⓘ
subject linked to: JSON Web Tokens (JWT)
SASL → relatedTo → OAuth 2.0 ⓘ
LTI → basedOn → OAuth 2.0 (later versions) ⓘ
linked to: OAuth 2.0
YouTrack → supportsAuthentication → OAuth 2.0 ⓘ
SAML → competesWith → OAuth 2.0 ⓘ
Google Sign-In → supportsProtocol → OAuth 2.0 ⓘ
Google+ Sign-In (legacy) → supports → OAuth 2.0 ⓘ
subject linked to: Google+ sign-in (legacy)
full-stack-fastapi-template → usesTechnology → OAuth2 ⓘ
linked to: OAuth 2.0
Mastodon → supportsProtocol → OAuth 2.0 ⓘ
Azure Active Directory Graph API → authenticationMethod → Azure AD OAuth 2.0 ⓘ
linked to: OAuth 2.0
UserInfo Endpoint → isProtectedBy → OAuth 2.0 ⓘ
DICOMweb → supportsSecurity → OAuth 2.0 (profile-dependent) ⓘ
linked to: OAuth 2.0
RFC 5849 → relatedTo → OAuth 2.0 ⓘ
OAuth Working Group → standardizes → OAuth 2.1 ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Device Authorization Grant ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Token Revocation ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Token Introspection ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 for Native Apps ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 for Browser-Based Apps ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Rich Authorization Requests ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Pushed Authorization Requests ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Incremental Authorization ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 JWT Secured Authorization Request (JAR) ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Step-up Authentication Challenge Protocol ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Resource Indicators ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Token Exchange ⓘ
linked to: OAuth 2.0
OAuth Working Group → standardizes → OAuth 2.0 Security Topics ⓘ
linked to: OAuth 2.0