What is OAuth?
The protocol behind every "Continue with Google" button and every app that asks for access to your calendar.
In short
OAuth 2.0 is an open standard that lets an app get limited access to a user's account on another service, such as their Gmail or calendar, without ever seeing their password. The user approves specific permissions, called scopes, and the app receives a token it can use until it expires or is revoked.
Also called: OAuth 2.0
Why it matters when your prototype goes to production
OAuth shows up in two ways. For sign-in, "Continue with Google" uses OpenID Connect, an identity layer on top of OAuth 2.0; providers such as Clerk run that flow for you. For integrations, your app asks a user for access to their account elsewhere, and then holds tokens that can act as them.
The second is where production risk lives. Those tokens are credentials: they belong encrypted on the server, never in the browser. Ask for the fewest scopes that do the job, because users see the list and reviewers check it.
An example of narrow scopes
Bell, an AI email assistant, connects to Gmail with access limited to reading and sending. It never asks for more than the product needs.
Common questions
What is the difference between OAuth and OpenID Connect?
OAuth grants an app access to resources. OpenID Connect is a thin identity layer on top of OAuth that also tells the app who the user is, which is what sign-in needs.
Can OAuth be used for single sign-on?
Yes, through OpenID Connect. SAML is the other common standard for enterprise single sign-on.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.