OAuth 2.0
OAuth 2.0 is a widely used authorization framework that enables applications to access protected resources securely without users having to disclose their credentials. Instead, access tokens are used that are time-limited and provided with specific permissions (scopes).
The framework defines four roles for this: the resource owner (user), the client (the accessing application), the authorization server (issues tokens) and the resource server (protects the data). Different flows exist for different scenarios; today, the authorization code flow with PKCE is recommended above all for web and mobile applications, and the client credentials flow for communication between services. Important for classification: OAuth 2.0 governs authorization, not authentication – identity verification is added by the standard OpenID Connect, which builds on it.
In API and microservices architectures, OAuth 2.0 is the de facto standard for access control: sensitive credentials are not exchanged between systems, permissions can be tailored granularly to the respective use case, and tokens can be specifically revoked in the event of misuse.