OAuth is a delegation protocol that allows users to delegate a subset of their rights to a piece of software to act on their behalf. It is not solely an authorization protocol but focuses on delegation, enabling users to grant permissions without giving away full account rights. This approach revolutionized conventional authorization methods and eliminated the need to provide extensive access to software for it to perform specific tasks.
OAuth is an open standard for access delegation. It lets users grant websites or applications access to their information on other websites, but without giving away passwords.
OpenID Connect is an identity layer on top of OAuth. Even if you haven’t programmed using OAuth and OpenID Connect, you’ve certainly used them for authentication on Google, Facebook, Spotify, and countless other services.
Authlete is a service that provides a set of APIs to implement OAuth authorization servers, and OpenID Connect identity providers.
Justin Richer is the Principal Architect at Authlete and is part of the working group that developed OAuth 2.0. He joins the podcast to talk about the history of OAuth, OAuth as a delegation protocol, the Authlete API, and much more.
Gregor Vand is a security-focused technologist, and is the founder and CTO of Mailpass. Previously, Gregor was a CTO across cybersecurity, cyber insurance and general software engineering companies. He has been based in Asia Pacific for almost a decade and can be found via his profile at vand.hk.
The post Authlete and Making OAuth Accessible with Justin Richer appeared first on Software Engineering Daily.