> ## Documentation Index
> Fetch the complete documentation index at: https://developers.pleo.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

export const WarningCallout = ({title, children}) => <div className="callout-box callout-warning">
    <div className="callout-row">
      <span className="callout-badge">
        <svg width="18" height="18" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 256 256" fill="currentColor"><path d="M215.46,216H40.54C27.92,216,20,202.79,26.13,192.09L113.59,40.22c6.3-11,22.52-11,28.82,0l87.46,151.87C236,202.79,228.08,216,215.46,216Z" opacity="0.2" /><path d="M236.8,188.09,149.35,36.22h0a24.76,24.76,0,0,0-42.7,0L19.2,188.09a23.51,23.51,0,0,0,0,23.72A24.35,24.35,0,0,0,40.55,224h174.9a24.35,24.35,0,0,0,21.33-12.19A23.51,23.51,0,0,0,236.8,188.09ZM222.93,203.8a8.5,8.5,0,0,1-7.48,4.2H40.55a8.5,8.5,0,0,1-7.48-4.2,7.59,7.59,0,0,1,0-7.72L120.52,44.21a8.75,8.75,0,0,1,15,0l87.45,151.87A7.59,7.59,0,0,1,222.93,203.8ZM120,144V104a8,8,0,0,1,16,0v40a8,8,0,0,1-16,0Zm20,36a12,12,0,1,1-12-12A12,12,0,0,1,140,180Z" /></svg>
      </span>
      <div>
        {title && <div className="callout-title">
            {title}
          </div>}
        <div className="callout-body">
          {children}
        </div>
      </div>
    </div>
  </div>;

<WarningCallout title="This page has now been ARCHIVED. Please visit:">
  * **[OAuth 2.0 Overview](/docs/current/authentication/oauth/oauth-overview)**
  * **[OAuth 2.0 Access to Staging Workflow Guide](/docs/current/guides/environment-access/staging-oauth-workflow)**
  * **[OAuth 2.0 Setup Workflow Guide](/docs/current/guides/oauth-workflow-guide)**
</WarningCallout>

## What is OAuth 2.0?

**OAuth 2.0** is an industry standard for secured authorisation of web applications, allowing them to request access to user-owned resources from external resource providers, without asking users for their access credentials, such as passwords.

A few important characteristics of OAuth 2.0:

* In order to grant access, OAuth 2.0 does not request for users' credentials.
* OAuth 2.0 also restricts actions — it keeps a check on what an external website/application performs on the resources hosted on other websites/applications.

## Roles

OAuth 2.0 is a standard designed for access delegation. This includes the following four roles participating in the OAuth 2.0 protocol (explained here in the context of integrating with Pleo):

* **Resource owner**: Pleo's customer - a company or an organisation (multi-entity set up) that owns a number of protected resources, such as accounting data, list of employees, etc.

* **Resource server**: Pleo APIs provides access to the protected resources.

* **Client** : Third-party applications that the Developer Partner wants to integrate with Pleo.

* **Authorisation server**: Pleo provides an OAuth 2.0 implementation that fulfils the following:

  * Allows clients to request access to resource servers.
  * Helps resources owners to grant access to clients.

## Use of OAuth 2.0 in Pleo

In Pleo, we provide an implementation of an OAuth 2.0 authorisation server to help you with the following:

* Integrate third-part applications with Pleo using OAuth 2.0 as the authorisation method.

* Use OAuth 2.0 to access the Pleo APIs.

## How to use OAuth 2.0?

In order to integrate your application with Pleo using OAuth 2.0, you must perform the following:

1. [Register your application](/docs/oauth-client-registration) and receive OAuth 2.0 client credentials - client identifier and client secret.
2. [Integrate an OAuth 2.0 client library](/docs/implementing-oauth-client-using-a-library) in your application.
3. [Configure your OAuth 2.0 client](/docs/client-configuration) to work with Pleo's authorisation server.

After completing these steps, users of your application could successfully and securely transition data from Pleo.
