"Sign in with Google" never gives the app your Google password — here's the trade

You approve on Google's page, the app gets a token and a little profile info, and that's one less password anyone can leak. Why it's often the safer…

Aliteq
Syntax · Build Editor

You now understand

OAuth lets you log in without giving the app your password

You now understand

You approve on the provider's own page, and can revoke access later

You now understand

The app receives a token plus only the limited profile info you approved

What this means for your app

Adding social login means you hold no passwords at all, which removes a whole class of risk. In return you're trusting the provider, and you still receive a token you must protect exactly like the…

Aliteq

Read the full story

"Sign in with Google" never gives the app your Google password — here's the trade

Read the full story on Aliteq