Security & Auth interview question

How does OAuth 2.0 work?

Short answer

OAuth 2.0 lets an application get limited access to a user’s resources without handling their password. The user signs in with an authorization server and approves scopes; the app receives an authorization code, exchanges it for an access token and calls the resource server with that token. For public clients, the code flow is protected with PKCE.

Roles

  • Resource owner — the user.
  • Client — the application requesting access.
  • Authorization server — authenticates the user and issues tokens.
  • Resource server — the API that accepts access tokens.

OAuth vs OpenID Connect

OAuth is about authorization — delegated access. OpenID Connect adds an identity layer on top, with an ID token that tells the client who the user is. “Sign in with …” buttons use OpenID Connect.

How to answer it in an interview

  • Explain why the implicit flow is discouraged and PKCE is recommended.
  • Mention short-lived access tokens with refresh tokens.

Walk into your next interview prepared

Start free, install the Windows app and run a practice session today.