OAuth 2.0
The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.
OAuth 2.0, defined in RFC 6749, is an authorisation framework that lets a third-party application obtain limited access to an HTTP service, either on behalf of a resource owner or on its own behalf. It separates four roles, the resource owner, the client, the authorisation server and the resource server, and replaces password sharing with tokens that carry a defined scope. Open banking APIs and the Model Context Protocol's HTTP authorisation are both built on it.
Agent Minute explains this term on 8 November 2026.
Related terms
Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.OAuth scopeA value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.Rich Authorization RequestsAn OAuth extension that carries structured details of the action being authorised, such as amount and payee.FAPI 2.0 Security ProfileAn OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.