Beyond the LoginBetaunderstand identity, one concept at a time

Grants, scopes, and consent

Understanding grants

When the printing application requests access to your photos, several related decisions are involved.

What is it asking to do? Who can authorize that access? What does the authorization server actually issue? What will the photo API permit?

Three terms help us describe different parts of that process: grant, scope, and consent.

An authorization grant is a credential representing authorization that a client can use to obtain an access token. In the authorization code flow, the authorization code serves that purpose.

A grant type identifies the method used at the token endpoint. For example, the authorization code grant and client credentials grant use different credentials and serve different situations.

You may also hear a product refer to a saved application connection as a "grant." That describes the continuing authorization relationship recorded by the product. When reading a protocol exchange, it helps to distinguish that stored relationship from the credential being presented in a particular token request.

Describing access with scopes

A scope describes an area of access. Our fictional photo service might define:

photos.read
albums.create
photos.delete

The printer could request photos.read because it needs to retrieve photos. It has no reason to request photos.delete to create a printed book.

Those names are examples. Their meaning comes from the service that defines and enforces them. Another photo service could use different names or divide its capabilities differently.

Scope names are not universal instructions that an API automatically understands. Adding photos.read to a token request does not grant access by itself. The authorization server must decide whether to allow the request, and the API must enforce the resulting authorization.

A scope may also leave important questions unanswered.

Does photos.read permit reading every photo in your library? Only a selected album? Photos shared with your account?

The scope name alone does not tell us. The service needs rules and, where necessary, additional information to express those restrictions. Later, Rich Authorization Requests will examine one way to describe access requirements in more detail.

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 1 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 1The printer requests photos.read and photos.delete, but the service grants only photos.read. What should the printer assume?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity