A mobile 311 app must call city APIs on a resident's behalf without embedding the resident's password in the app. Which technology best fits?
Select an answer to reveal the explanation.
Short Explanation
OAuth is like giving the 311 app a temporary valet ticket to specific APIs—not the resident's house keys. The app acts with a token instead of hauling around the real password.
Full Explanation
OAuth provides delegated authorization so applications obtain scoped tokens to call APIs without collecting or replaying the resource owner's password. Embedding shared secrets, sending directory passwords, or over-privileging the app are insecure anti-patterns.