---
term: "OAuth 2.0"
category: "Authentication and security"
url: https://agenticopenfinance.com/glossary/oauth-2
source: AgenticOpenFinance glossary
---

# OAuth 2.0

> The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.

OAuth 2.0, defined in RFC 6749, is an authorisation framework that lets a third-party application obtain limited access to an HTTP service, either on behalf of a resource owner or on its own behalf. It separates four roles, the resource owner, the client, the authorisation server and the resource server, and replaces password sharing with tokens that carry a defined scope. Open banking APIs and the Model Context Protocol's HTTP authorisation are both built on it.

Related terms: [Access token](https://agenticopenfinance.com/glossary/access-token.md), [OAuth scope](https://agenticopenfinance.com/glossary/oauth-scope.md), [Rich Authorization Requests](https://agenticopenfinance.com/glossary/rich-authorization-request.md), [FAPI 2.0 Security Profile](https://agenticopenfinance.com/glossary/fapi-2.md)
