OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist
OAuth checklist

Editor's Notes

  • #5 RFC only published in April 2010
  • #6 Authorization - used most of the time Authentication - 2 legged OAuth, “sign in with twitter”, no to be confused with OpenID Built as an Open Protocol on top of already existing solutions (Amazon,Yahoo)
  • #7 Authorization - used most of the time Authentication - 2 legged OAuth, “sign in with twitter”, no to be confused with OpenID Built as an Open Protocol on top of already existing solutions (Amazon,Yahoo)
  • #13 OOB = Out of Band aka PIN OAuth
  • #19 Example from twitter connections settings
  • #20 Example from facebook where you can revoke apps and also individual permissions