Authentication and security

OAuth 2.0

The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.

OAuth 2.0, defined in RFC 6749, is an authorisation framework that lets a third-party application obtain limited access to an HTTP service, either on behalf of a resource owner or on its own behalf. It separates four roles, the resource owner, the client, the authorisation server and the resource server, and replaces password sharing with tokens that carry a defined scope. Open banking APIs and the Model Context Protocol's HTTP authorisation are both built on it.

Agent Minute explains this term on 8 November 2026.

Related terms