"Log in with Google" — without Google ever seeing the other site's password.
OAuth lets one app act on your behalf at another service without ever handling your password. Instead of credentials, apps get a scoped, revocable token.
The authorization-code flow
Redirect. The app sends you to the provider with the scopes it wants.
Consent. You authenticate with the provider and approve (or deny) those scopes.






