What is OAuth — letting an AI agent into your account without your password
OAuth is a web standard for delegating limited access to your account to another app or AI agent without giving it your password. You approve the request on the service's own sign-in page, for example 'allow this app to read your email', and the service gives the app an access token with a defined scope and expiry instead of your password. You can revoke that token at any time. OAuth 2.0 became an internet standard (RFC 6749) in 2012, and 'Sign in with Google' adds an identity layer called OpenID Connect on top. The Personal Agent Protocol announced in October 2026 and remote connections in MCP both build on OAuth
The three lines
- Definition — delegation by scoped, expiring tokens instead of passwords; RFC 6749 (2012)
- Flow — app asks → you approve on the service's own page → app gets a token → revoke anytime
- AI era — the Personal Agent Protocol and MCP use OAuth to split read and write permissions
Key questions
- OAuth explained simply
- **Instead of a master key, you hand over a keycard for one floor, for one day.** | Analogy | OAuth term | |---|---| | Hotel guest (you) | Resource owner | | Front desk | Authorization server (Google, etc.) | | Keycard | Access token | | One floor | Scope | | One day | Expiry | | Reporting a lost card | Revoking the token |
- Is it safe to connect an AI agent to my account
- **Much safer via OAuth than typing your password, but check the scopes.** | Check | How | |---|---| | Page address | Is the approval page on the service's real domain? | | Permissions | Does a summarizer ask to send or delete? | | Revocation | Remove unused apps under connected apps | | Warning signs | Unknown connections, emails you didn't send |
- How to revoke OAuth app access
- **Every major service lists connected apps in its security settings.** | Service | Typical location | |---|---| | Google | Account → Security → Third-party apps & services | | Microsoft | Account → Privacy → Apps and services | | GitHub | Settings → Applications | Removing an app invalidates its tokens.
To have an AI assistant tidy your inbox, it has to get into your inbox. You should not give it your password. The standard that has solved this for more than 15 years is OAuth — the technology behind "Sign in with Google" buttons. The Personal Agent Protocol that Meta and Sierra announced on October 6, 2026 also builds its agent sign-in rules on OAuth. Here is how it works and what to check when an AI agent asks for access.
1. The problem OAuth solves: no more password sharing
Before OAuth, a third-party app that needed your data asked for your username and password. It could then do anything in your account; if it was breached, your password leaked; the only way to cut it off was to change your password.
| Typing your password | OAuth | |
|---|---|---|
| What the app gets | Your password | An access token |
| Scope | Everything | Only what you approved |
| Lifetime | Until you change your password | Defined, usually short |
| Cutting off | Change password | Disconnect that app only |
| If the app is breached | Password exposed | Token exposed, revocable |
It is like giving someone a keycard for one floor, valid for one day, rather than the master key.
2. How it works, in four steps
| Step | What happens | What you see |
|---|---|---|
| ① Request | The app or agent sends you to the service's sign-in page asking for, say, read access to email | "Continue with Google" |
| ② Consent | You sign in on the service's own page and approve the listed permissions | "This app wants to…" |
| ③ Issue | The service gives the app a short-lived code, which it exchanges for an access token | You return to the app |
| ④ Use | The app calls the API with the token, within scope; a refresh token renews it | — |
The key is step ②: your password is entered only on the service's own page, never seen by the app. The extra code exchange in ③ keeps tokens out of browser address bars. For mobile and browser apps that cannot keep secrets, PKCE (RFC 7636) makes an intercepted code useless.
| Term | Meaning |
|---|---|
| Access token | The pass shown with each request; minutes to hours |
| Refresh token | Used to get new access tokens; longer-lived |
| Scope | Permission boundary, e.g., read mail, write calendar |
| Authorization server | Handles sign-in and consent; issues tokens |
3. Sign-in is not the same as permission
OAuth is about delegating access, not proving who you are. Identity — "this is the same person" — comes from OpenID Connect (2014), layered on OAuth.
| Year | Standard | Role |
|---|---|---|
| 2007–2010 | OAuth 1.0 | First delegation spec, complex signatures |
| 2012 | OAuth 2.0 (RFC 6749) | Today's de facto web standard |
| 2014 | OpenID Connect | Adds identity on top of OAuth |
| 2015 | PKCE (RFC 7636) | Protects mobile and browser apps |
| In progress | OAuth 2.1 | Drops insecure legacy flows; PKCE by default |
4. Why it matters more with AI agents
A person sees what happens after each click. An agent can send dozens of requests while no one watches, so the permissions granted at the start set the size of any accident.
| Standard or product | How it uses OAuth |
|---|---|
| Personal Agent Protocol (Oct 2026) | Agent sessions on OAuth; guest → sign-in → customer picks read-only or write |
| MCP remote servers | OAuth to authenticate AI connections to external tools |
| Chatbot connectors for mail, calendar, drive | Mostly via OAuth consent screens |
Write access lets an agent send email, change orders or delete files. Combined with prompt injection — hidden instructions in a web page that hijack an agent — permissions you granted can effectively pass to an attacker.
5. What to check
| Situation | Check |
|---|---|
| Consent screen appears | Is it on the service's real domain? Beware fake sign-in pages |
| Permission list | Does a summarizer request send or delete rights? |
| Connecting an AI agent | Start read-only; grant write only when needed |
| Routine | Remove unused apps from "connected apps" |
| Something odd | Unknown connections or sent mail you didn't write → disconnect and change password |
6. Frequently asked
| Question | Answer |
|---|---|
| Does OAuth make hacking impossible? | No. It beats password sharing but cannot stop fake consent pages or over-broad approvals |
| What if a token is stolen? | Disconnect the app; the token dies and your password stays safe |
| Is social login the same thing? | Social login is the best-known use of OAuth 2.0 plus OpenID Connect |
| How is it pronounced? | "Oh-auth" — short for Open Authorization |
7. What remains unconfirmed
- The Personal Agent Protocol's exact OAuth flows and token formats await its v0.1 spec.
- OAuth 2.1 is not yet a final standard.
- Settings menu locations change with app updates.