An open authorization framework that lets a user grant a third-party application limited access to their resources on another service without sharing their password. The application receives a time-limited access token, issued after the user consents, which it presents to the service to perform only the permitted actions.

