METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryOTechnical words in the news

OAuth

An authorization method that lets one service borrow a limited, predefined set of permissions from another without ever handing over your password

In plain words

OAuth lets one service access a specific part of your information on another service without ever learning your password. Think of it like a hotel: instead of giving the cleaning staff a master key to every room, you hand them a keycard that only opens one room. The master key (your password) stays in your hands, and only a keycard (permission) is issued for exactly what's needed.

You've probably seen this in action when logging into an app with your Google account and a screen pops up asking, "Allow this app to access your email and profile information?" That's OAuth at work. Once you tap allow, the app can use only the information you approved, without ever knowing your Google password.

At companies, when multiple employees connect tools like Slack or Notion to an AI system, each person traditionally had to go through this permission screen individually. More recently, a new approach has emerged where a company admin can set permission rules in advance, so individual employees no longer need to trigger that approval screen every time.

How it shows up in the news

The article includes a line like: "Until now, users had to go through individual OAuth authorization for each tool before it could be connected." Here, OAuth authorization refers to the process where a separate permission screen appears each time a user connects a tool like Slack or Notion to an AI, granting it access. A common misunderstanding is that OAuth hands your actual password over to another service — in reality, your password stays put, and only a limited scope of permission is lent out.

Try it yourself

Open an app you use regularly and tap the button to log in with your Google or Apple account. Right before logging in, check whether a screen appears asking something like "Allow this app to access your email and profile information?" If that screen breaks down the specific pieces of information you can approve, that's OAuth requesting permissions in scoped pieces. In your account settings, look for something like "Connected apps" or "Manage third-party access" — you'll find a list of which services you've granted which permissions to, and you can revoke them there.

See also

Stories using this term

Browse every entry