Instead of using the bloated OAuth multiple requests back and forth, permission keys, auth keys, consumer secrects, etc, etc. you can simply add an additional header saying "client id" which the service provider can then use to "secure" his er her service as he sees fit.
OAuth is a bloated attempt to paper around the simple solution so that the astronaut architects who made it can feel smug about themselves.
OAuth solves no problems, helps nobody and has (drastically) polluted our ecosystem. To hell with that shit.
OAuth 2.0 is basically that + a standardized protocol for requesting a "client id", which is why it's completely insecure over standard HTTP.
That means you have to agree on a way of exchanging that client ID.
Which at it's simplest is what OAuth 2 does with bearer tokens. If you have no use for the other parts of the spec then just ignore them, it's all optional and you only need to implement it if you need it.
You must not be developer. OAuth 2.0 is not bloated and pretty much 2 steps with a clause to never use it via HTTP. How could it be more simple?
1) Redirect the user 2) Do a POST request to acquire an access token
How is that a pain?
3) When you make an authenticated API call, send the access token along with the request, and make sure you're using HTTPS.
The HTTPS part is important to give a bunch of the security guarantees than OAuth 1 gives you with plain HTTP and some complicated crypto dancing around.