Gara qabiyyee ijyootti utaali
JobCannon
Dandeettiiwwan hundaa

OAuth 2.0 OpenID

⬢ SADARKAA 2Teeknikaalaa
Ol'aanaa
Dhiibbaa miindaa
Ji'oota 3
Yeroo barachuuf fudhatu
Ulfaataa
Sadarkaa rakkinaa
—
Hojiiwwan Ogummaa
Gabaabinaan

OAuth 2.0 OpenID is the protocol for delegated authentication and authorization. OAuth handles 'authorization' (accessing user data on behalf of user), OpenID handles 'authentication' (proving who you are). Used everywhere: Google Login, GitHub, Stripe. Senior engineers earn 25-35% premium for security expertise. Time to mastery: 10-14 weeks. Sits between cryptography and application security.

OAuth 2.0 OpenID maali?

OAuth 2.0 is the industry standard for authorization (granting third-party applications access to user data without sharing passwords). OpenID Connect is an identity layer built on OAuth 2.0 for authentication (proving who a user is). Together, they enable "Sign in with Google," "Login via GitHub," and similar patterns. The flow: user clicks "Login with Google" → redirected to Google → user grants permission → redirected back with access token → app uses token to access user data. User never shares password; only Google knows it.

🔧 MEESHAALEE & SIRNA NAANNOO
OAuth 2.0 providers (Google, GitHub, Microsoft)Passport.jsAuth0Supabase AuthJWT librariesPostmanDebugging proxies

📋 Osoo hin jalqabin dura

💰 Miindaa naannoodhaan

NaannooJalqabaaGiddu-galeessaAngafa
USA$85k$140k$230k
UK£52k£85k£140k
EU€58k€95k€155k
CANADAC$90kC$145kC$240k

⚖ Walbira qabi

❓ Gaaffiiwwan Deddeebi'an

What's the difference between OAuth and OpenID?
OAuth = authorization (I allow app to access my calendar). OpenID = authentication (prove I'm John). OAuth 2.0 + OpenID Connect = full solution (prove who you are, grant access).
Should I implement OAuth or use Auth0?
Use Auth0 (or Supabase Auth) first. Building OAuth from scratch is complex (state management, PKCE, refresh tokens). Only build custom if Auth0 doesn't fit (very rare).
What's the PKCE flow?
Proof Key for Code Exchange. Mobile/SPA apps can't keep secrets, so PKCE adds challenge/verifier. Prevents authorization code interception. Best practice for all OAuth flows now.
How do I refresh access tokens?
OAuth provider gives access token + refresh token. Access token expires (1h). Refresh token is long-lived (30 days). When access expires, use refresh to get new access without user re-authenticating.
What are scopes in OAuth?
Scopes limit access. `openid profile email` = basic user info. `calendar:read` = read calendar. `admin:write` = write as admin. User grants scope at login.

Dandeettiin kun isiniif ta'uu isaa hin beektanii?

Wal-gita Hojii fudhadhaa — daandiiwwan sirrii isiniif yaada kennina.

Dandeettiiwwan naaf mijatan argadhaa →

Daandii ogummaa keessan isa gaarii argadhaa

Hojiiwwan ogummaa 2,521 keessaa wal-madaalchisuu dandeettii irratti hundaa'e. Tola.

Wal-gita Hojii fudhadhaa — tola →