You click "Sign in with Google" on some app you've never used before. A popup flashes, you pick your account, and three seconds later the app knows your name and email. You never typed a password into that app. It never saw your Google credentials. So how does it know who you are?
That's OAuth 2.0 and OpenID Connect doing their thing. Almost every app you use either consumes or implements this flow, and the confusion between OAuth and OIDC causes real security bugs in production. Worth understanding properly.
Remember the old days when apps would ask "give us your Gmail password so we can find your friends"? You'd hand over your actual credentials to some random third party. They could read your email, send messages as you, change your password. Terrible.
OAuth 2.0 fixes this with delegated authorization. Instead of giving an app your password, you tell Google "hey, let this app see my basic profile info." Google gives the app a limited, revocable token. The app never touches your credentials.
Four roles are involved:







