Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, an app is explicitly forbidden from ever asking for login/password. Twitter/Facebook do the same thing.

Instead, you use OAuth to fetch an access token. This is far better for the user - they can revoke your app's access without changing passwords, and without all their other apps losing their connections.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: