# access-token

Source: https://startwithidentity.com/glossary/access-token/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

A short-lived credential a client presents to a resource server to access protected data. Access tokens are typically opaque or JWT-formatted, with lifetimes measured in minutes. Treat them as bearer secrets: anyone holding the token can use it.

Because most access tokens are bearer tokens, possession is authorization: anyone holding one can use it until it expires. That is why token theft from browser sessions and infostealer logs has displaced password phishing as the dominant account-takeover path, and why a password reset does nothing to contain it. Short lifetimes limit the window; sender-constraining with DPoP or mTLS closes it by binding the token to a key the thief does not have.

See also: [OAuth 2.0](https://startwithidentity.com/standards/oauth-2-0/), [refresh token](https://startwithidentity.com/glossary/refresh-token/), [DPoP](https://startwithidentity.com/glossary/dpop/), [token theft](https://startwithidentity.com/glossary/token-theft/)
