OAuth (“sign in with…”).
A valet key: you let an app do one specific thing without ever handing over your real password.
- Your password? …no.1
An app wants your photos. The old way would be to hand it your password — the keys to everything.
- It’s me. Here’s my real key.2
Instead you go to the one you already trust (say, Google) and prove who you are there.
- May I have his photos?3
The app never sees that. It just asks the trusted service on your behalf.
- Photos only.4
You approve exactly what it may touch — “photos only, not your email.”
- 5
The service hands the app a limited key (a token), not your password.
- Revoke? Done.6
The app uses that key for its one job — and you can revoke it any time without changing your password.
Semicolony semicolony.dev/eli5/oauth/comic