Skip to content
TEN Brief Ten verified stories a day 2026.10.08 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 3 min read · Reference

What is OAuth — letting an AI agent into your account without your password

OAuth is a web standard for delegating limited access to your account to another app or AI agent without giving it your password. You approve the request on the service's own sign-in page, for example 'allow this app to read your email', and the service gives the app an access token with a defined scope and expiry instead of your password. You can revoke that token at any time. OAuth 2.0 became an internet standard (RFC 6749) in 2012, and 'Sign in with Google' adds an identity layer called OpenID Connect on top. The Personal Agent Protocol announced in October 2026 and remote connections in MCP both build on OAuth

A hand passing a blank key card across a sunlit hotel front desk

The three lines

  • Definition — delegation by scoped, expiring tokens instead of passwords; RFC 6749 (2012)
  • Flow — app asks → you approve on the service's own page → app gets a token → revoke anytime
  • AI era — the Personal Agent Protocol and MCP use OAuth to split read and write permissions

Key questions

OAuth explained simply
**Instead of a master key, you hand over a keycard for one floor, for one day.** | Analogy | OAuth term | |---|---| | Hotel guest (you) | Resource owner | | Front desk | Authorization server (Google, etc.) | | Keycard | Access token | | One floor | Scope | | One day | Expiry | | Reporting a lost card | Revoking the token |
Is it safe to connect an AI agent to my account
**Much safer via OAuth than typing your password, but check the scopes.** | Check | How | |---|---| | Page address | Is the approval page on the service's real domain? | | Permissions | Does a summarizer ask to send or delete? | | Revocation | Remove unused apps under connected apps | | Warning signs | Unknown connections, emails you didn't send |
How to revoke OAuth app access
**Every major service lists connected apps in its security settings.** | Service | Typical location | |---|---| | Google | Account → Security → Third-party apps & services | | Microsoft | Account → Privacy → Apps and services | | GitHub | Settings → Applications | Removing an app invalidates its tokens.

To have an AI assistant tidy your inbox, it has to get into your inbox. You should not give it your password. The standard that has solved this for more than 15 years is OAuth — the technology behind "Sign in with Google" buttons. The Personal Agent Protocol that Meta and Sierra announced on October 6, 2026 also builds its agent sign-in rules on OAuth. Here is how it works and what to check when an AI agent asks for access.

1. The problem OAuth solves: no more password sharing

Before OAuth, a third-party app that needed your data asked for your username and password. It could then do anything in your account; if it was breached, your password leaked; the only way to cut it off was to change your password.

Typing your passwordOAuth
What the app getsYour passwordAn access token
ScopeEverythingOnly what you approved
LifetimeUntil you change your passwordDefined, usually short
Cutting offChange passwordDisconnect that app only
If the app is breachedPassword exposedToken exposed, revocable

It is like giving someone a keycard for one floor, valid for one day, rather than the master key.

2. How it works, in four steps

StepWhat happensWhat you see
① RequestThe app or agent sends you to the service's sign-in page asking for, say, read access to email"Continue with Google"
② ConsentYou sign in on the service's own page and approve the listed permissions"This app wants to…"
③ IssueThe service gives the app a short-lived code, which it exchanges for an access tokenYou return to the app
④ UseThe app calls the API with the token, within scope; a refresh token renews it—

The key is step ②: your password is entered only on the service's own page, never seen by the app. The extra code exchange in ③ keeps tokens out of browser address bars. For mobile and browser apps that cannot keep secrets, PKCE (RFC 7636) makes an intercepted code useless.

TermMeaning
Access tokenThe pass shown with each request; minutes to hours
Refresh tokenUsed to get new access tokens; longer-lived
ScopePermission boundary, e.g., read mail, write calendar
Authorization serverHandles sign-in and consent; issues tokens

3. Sign-in is not the same as permission

OAuth is about delegating access, not proving who you are. Identity — "this is the same person" — comes from OpenID Connect (2014), layered on OAuth.

YearStandardRole
2007–2010OAuth 1.0First delegation spec, complex signatures
2012OAuth 2.0 (RFC 6749)Today's de facto web standard
2014OpenID ConnectAdds identity on top of OAuth
2015PKCE (RFC 7636)Protects mobile and browser apps
In progressOAuth 2.1Drops insecure legacy flows; PKCE by default

4. Why it matters more with AI agents

A person sees what happens after each click. An agent can send dozens of requests while no one watches, so the permissions granted at the start set the size of any accident.

Standard or productHow it uses OAuth
Personal Agent Protocol (Oct 2026)Agent sessions on OAuth; guest → sign-in → customer picks read-only or write
MCP remote serversOAuth to authenticate AI connections to external tools
Chatbot connectors for mail, calendar, driveMostly via OAuth consent screens

Write access lets an agent send email, change orders or delete files. Combined with prompt injection — hidden instructions in a web page that hijack an agent — permissions you granted can effectively pass to an attacker.

5. What to check

SituationCheck
Consent screen appearsIs it on the service's real domain? Beware fake sign-in pages
Permission listDoes a summarizer request send or delete rights?
Connecting an AI agentStart read-only; grant write only when needed
RoutineRemove unused apps from "connected apps"
Something oddUnknown connections or sent mail you didn't write → disconnect and change password

6. Frequently asked

QuestionAnswer
Does OAuth make hacking impossible?No. It beats password sharing but cannot stop fake consent pages or over-broad approvals
What if a token is stolen?Disconnect the app; the token dies and your password stays safe
Is social login the same thing?Social login is the best-known use of OAuth 2.0 plus OpenID Connect
How is it pronounced?"Oh-auth" — short for Open Authorization

7. What remains unconfirmed

  • The Personal Agent Protocol's exact OAuth flows and token formats await its v0.1 spec.
  • OAuth 2.1 is not yet a final standard.
  • Settings menu locations change with app updates.

Sources

  1. IETF — RFC 6749: The OAuth 2.0 Authorization Framework
  2. IETF — RFC 7636: Proof Key for Code Exchange (PKCE)
  3. OpenID Foundation — OpenID Connect Core 1.0
  4. Sierra — Introducing Personal Agent Protocol
  5. Model Context Protocol — Authorization specification

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • Which OAuth flows and token formats the Personal Agent Protocol uses will be known when its v0.1 spec is published.
  • Menu locations for connected apps change with app updates.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related