Glossary · Security & Resilience
What is OAuth 2.0?
Short answer
OAuth 2.0 is an authorisation framework that lets an application access a user’s data in another service without ever seeing the user’s password. The user approves the access on the service’s own login page, and the application receives a limited, revocable access token for specific permissions (scopes). “Sign in with Google” and connecting apps to GitHub use OAuth.
How the authorisation code flow works
- Your app redirects the user to the provider (say, Google) with the scopes it wants and a random
statevalue. - The user signs in there and approves.
- The provider redirects back to your app with a short-lived authorisation code.
- Your server exchanges the code, together with its client secret or a PKCE verifier, for an access token and often a refresh token.
- Your app calls the provider’s API with the access token until it expires, then uses the refresh token to get a new one.
OAuth, OpenID Connect and JWT
OAuth is about authorisation (what an app may do). OpenID Connect adds authentication (who the user is) on top, returning an ID token, which is a JWT. “Sign in with…” buttons use OpenID Connect.
Security essentials
- Use the authorisation code flow with PKCE for every client, including single-page and mobile apps; the implicit flow is deprecated.
- Always check the
stateparameter to prevent cross-site request forgery. - Request the smallest scopes you need and store tokens encrypted.
- Register exact redirect URLs, never wildcards.
In Laravel, Socialite handles “sign in with” providers and Passport issues OAuth tokens for your own API.

