Learn OAuth 2.0
See how apps get permission to use your data without ever seeing your password. OAuth 2.0 has a few different ways of doing this, called flows. Pick one below to read a short explanation and step through it. Not sure where to start? Try Authorization Code.
Authorization Code
For web apps with a server
A user signs in, and your server gets the tokens
Client Credentials
For server-to-server calls
A program signs in as itself, with no user involved
PKCE
For mobile and browser apps
Authorization Code, made safe for apps that cannot keep a secret
Refresh Token
For staying signed in
Trade a long-lived refresh token for a new access token, with no new login
Device Authorization
For TVs and gadgets
Approve a login on your phone for a device with no keyboard
OpenID Connect
For "Sign in with…" buttons
Authorization Code plus an ID token that tells the app who you are