# bearer-token

Source: https://startwithidentity.com/glossary/bearer-token/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

A bearer token is a credential that grants access to whoever presents it, with no proof that the presenter is the party it was issued to. OAuth 2.0 defines how bearer tokens are sent in [RFC 6750](https://www.rfc-editor.org/rfc/rfc6750).

Most OAuth access tokens, browser session cookies and API keys behave as bearer credentials, which is why stealing one is as good as stealing the login: the thief replays it and the server cannot tell the difference. The defenses are to keep bearer tokens short-lived, narrowly scoped and revocable, and, where the risk justifies it, to use sender-constrained tokens that are bound to a key the client must prove it holds, through [DPoP](https://startwithidentity.com/glossary/dpop/) (RFC 9449) or [mutual TLS](https://startwithidentity.com/glossary/mtls/) (RFC 8705). Bearer credentials also hide in places that do not look like tokens: in September 2026, researchers showed that [GitLab's incoming email address works as a non-expiring token](https://startwithidentity.com/blog/2026-09-23-gitlab-incoming-email-token-lets-anyone-commit-and-run-ci-as-you/) that can commit code as its owner.

See also: [access token](https://startwithidentity.com/glossary/access-token/), [token theft](https://startwithidentity.com/glossary/token-theft/), [session hijacking](https://startwithidentity.com/glossary/session-hijacking/), [token replay on unbound endpoints](https://startwithidentity.com/techniques/token-replay-unbound-endpoint/)
