OAuth
BackendSigning in via another provider.
The user authenticates with Google or GitHub, who then tell your app who they are. You never see the password, so you cannot leak it. Has enough subtle failure modes that you should always use a library.
See also Authentication, Identity provider, Token