OAuth 2.0 Authorization Flows structure how permissions are brokered between the resource owner, client, and authorization server. They define roles, redirect/callback mechanisms, token artifacts, and state transitions to mitigate attacks such as code interception or token leakage. The concept is technology-agnostic yet primarily security-driven.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
OAuth 2.0 is an authorisation framework that lets an application obtain limited access to protected resources without sharing the user’s password.
OAuth 2.0 grew from the problem of granting controlled access to services for third-party applications without sharing credentials. RFC 6749, published in 2012, formalised roles, tokens, and flows; later RFCs added security details.
A person grants a client consent through an authorisation server. The client receives a limited access token and presents it to the resource server; roles and redirects require precise protection.
This role can grant access to protected resources.
A short-lived code is exchanged for a token through a protected back channel.
Scopes limit the permissions represented by a token.
OAuth 2.0 separates delegated access from password handling and enables granular permissions. Redirect protection, PKCE, token lifetime, scope checks, and the distinction from authentication are key design concerns.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.