Product → Web Applications
OAuth
An authorization framework for delegated access to protected resources.
Motivation
OAuth exists because real systems need a practical way to handle a recurring engineering problem. Understanding it helps you see why nearby concepts in the graph matter rather than memorizing isolated definitions.
Where it fits
OAuth belongs to the product track in the web applications layer. It is usually learned together with concepts such as Authorization, API.
Mental model
Think of OAuth as one piece of a larger system. It either provides a capability, constrains how other parts work, or gives engineers a shared vocabulary for making design decisions.
Example in practice
When engineers discuss OAuth, they usually care about trade-offs: what problem it solves, what complexity it adds, and what assumptions it makes about the surrounding system.
Common mistakes
- Treating OAuth as a definition to memorize rather than a tool for reasoning.
- Ignoring the layer it belongs to and applying it at the wrong abstraction level.
- Forgetting the operational or design trade-offs it introduces.