OAuth is for authorization, not authentication OAuth is for authorization, not authentication OAuth is for authorization, not authentication OAuth is for authorization, not authentication OAuth is for authorization, not authentication OAuth is for authorization, not auth'n
1
3
Replying to @aaronpk
I like this analogy! A couple things that could make it better, especially for those who misuse/abuse OAuth for authentication:
2
1
1. Possession of the hotel keycard does *NOT* in any way prove you are the person who checked into the room it grants access to. Nobody should use the keycard to try to figure out who the person is.
1