{
  "id": 13654674,
  "title": "\"Sign in with Google\": Why It Bounces You Out and Back",
  "url": "https://urgent.news/2026/10/11/sign-in-with-google-why-it-bounces-you-out-and-back",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T05:47:18.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/autional/sign-in-with-google-why-it-bounces-you-out-and-back-3la9"
  },
  "original_language": "en",
  "account": "Clicking the \"Sign in with Google\" button takes you to Google's site for approval, then back to the original site with a one-time authorization code. This passcode allows the original site to access your Google account without knowing your password, creating a secure single-use ticket. The original site is not storing your password and can only use the passcode to access your account under specific conditions and for a limited time.\n\nThis system was introduced to replace older methods where passwords were shared with third-party sites, which was risky as passwords were often stored in plain text and could potentially be misused. The new system maintains your password's security while still allowing third-party services to access your account.\n\nThe approval step is crucial as it gives you a clear view of what permissions you are granting. However, people often make mistakes when approving these requests, such as not fully reading the consent prompt or not realizing that the third-party app can access various parts of their Google account like email and calendar.\n\nWhile \"Sign in with X\" doesn't guarantee the security of the third-party site, it does ensure that your password isn't shared. OAuth is an authorization protocol, not a login protocol, and its latest version includes mandatory Proof Key for Code Exchange (PKCE) for enhanced security.\n\nYou can revoke access to third-party apps under 'authorized apps' at any time. So even if a malicious app gets your passcode, it can't be used indefinitely and you have the ability to limit its access.",
  "summary": "You click \"Sign in with Google.\" The page jumps away, jumps back a second later, and you are in. So why the round trip — why not just type something on this page? Because the safe way is to never hand over your password . The old way: hand over your password Twenty years ago, if a site wanted to read your data somewhere else, you gave it your password. Convenient — and costly: It stored your…",
  "key_points": [
    "Clicking \"Sign in with Google\" redirects to Google's approval page",
    "Passcode grants temporary access to Google account without sharing password",
    "Users can revoke app access anytime via \"authorized apps\""
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}