Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
OAuth 2.0: The Complete Guide
Rating: 4.1 out of 5(150 ratings)
711 students

OAuth 2.0: The Complete Guide

Covering OAuth 2.0 Workflows, Endpoints, Scopes, Tokens: JWTs and API Security. Real-life examples included!
Last updated 10/2023
English
English [Auto],

What you'll learn

  • Deep Understanding of the OAuth 2.0 Protocol
  • Deep dive into Tokens, their Types and Lifetime
  • How is OAuth actually working
  • OAuth Grant Types
  • What is JWT and its Structure
  • Use OAuth to Protect your APIs
  • OAuth Endpoints
  • OAuth Scopes
  • Hand-on practice examples to access Public APIs using OAuth 2.0
  • Why Social and Internet Applications give us the option to sign up using other applications

Course content

5 sections17 lectures1h 56m total length
  • What is OAuth?1:44

    Understand how OAuth grants temporary, limited access to a resource by authorizing a second app to act on your behalf. Learn that OAuth is an authorization or delegation protocol.

  • The General OAuth Flow Explained6:50

    Explore the general oauth flow, showing how a third-party app requests limited user data from another service, prompts for consent, and uses an authorization token to access data over time.

  • OAuth Terminology and Key Components8:24

    Explore OAuth terminology and key components, including resource, resource owner, resource server, authorization server, client, and access tokens, and learn how scopes govern access in the authorization flow.

  • OAuth Detailed Workflows8:58

    Explore the authorization code and implicit OAuth 2.0 workflows, detailing how authorization server, resource server, resource owner, and client interact to grant access tokens.

  • What is OAuth used for?6:42

    Understand how OAuth enables access delegation and why it handles authorization rather than authentication, letting apps access only needed data from services like Google Drive.

  • OAuth Scopes9:25

    Learn how OAuth 2.0 scopes limit app access and differentiate read versus write permissions. See real-world examples from GitHub and Dropbox to secure user authorization.

  • OAuth Endpoints9:06

    Explore how OAuth 2.0 endpoints drive authorization and access token flows, including the authorized and token endpoints, authorization code and implicit flows, scopes, and JWT-based access tokens.

  • OAuth Best Practices10:31

    Learn essential OAuth 2.0 best practices, including enforcing https, protecting client secrets on the server, validating tokens, using minimal scopes, rate limiting, and transparent user permissions.

Requirements

  • No prerequisites needed for this course

Description

OAuth 2.0 has become the web-industry standard protocol for providing secure access to web APIs, allowing applications to access users' data without compromising security and actually passing their password around. Companies around the world add OAuth to their APIs to enable secure access from their own mobile apps and third-party IoT devices and even access to banking APIs. So if you think about the big names in the technology industry, you can pretty much bet they have OAuth implemented.

With that being said, it is pretty obvious that this skill will improve by a mile your software developer abilities and will make you much more valuable in the work field.

If you're building an API, you'll learn in this tutorial the differences and tradeoffs between different access token formats, including JWT, how to choose an appropriate access token lifetime, and how to design scopes to protect various parts of your APIs.


By the end of this course, you’ll understand:

  • The problems OAuth was created to solve

  • The actual types of workflows regarding OAuth detailed in steps

  • The basics of OAuth 2.0 including what it is, how it is used, and what it is used for.

  • OAuth 2.0 Endpoints that you can call

  • OAuth 2.0 Terminology and key components

  • Deep dive into tokens and their types

  • JWT and its structure and also how they work

So, if all of this sounds interesting, I look forward to seeing you guys in the lectures! :)

Who this course is for:

  • This course is for beginners in API Security and OAuth 2.0