How does OAuth 2.0 work?
OAuth 2.0 lets an application get limited access to a user’s resources without handling their password. The user signs in with an authorization server and approves scopes; the app receives an authorization code, exchanges it for an access token and calls the resource server with that token. For public clients, the code flow is protected with PKCE.