User-Managed Access (UMA 2.0) is a Kantara Initiative profile of OAuth 2.0 that lets a resource owner control authorization for protected resources across services. It introduces an authorization server that mediates access on the owner's policy terms.