Bearer Token
A bearer token is a credential that grants access to whoever presents it, with no proof that the presenter is the party it was issued to. OAuth 2.0 defines how bearer tokens are sent in RFC 6750.
Most OAuth access tokens, browser session cookies and API keys behave as bearer credentials, which is why stealing one is as good as stealing the login: the thief replays it and the server cannot tell the difference. The defenses are to keep bearer tokens short-lived, narrowly scoped and revocable, and, where the risk justifies it, to use sender-constrained tokens that are bound to a key the client must prove it holds, through DPoP (RFC 9449) or mutual TLS (RFC 8705). Bearer credentials also hide in places that do not look like tokens: in September 2026, researchers showed that GitLab's incoming email address works as a non-expiring token that can commit code as its owner.
See also: access token, token theft, session hijacking, token replay on unbound endpoints
Related on Start with Identity
- GlossaryDevice Bound Session Credentials (DBSC)
Device Bound Session Credentials (DBSC) is a web standard that binds a browser session to a private key held in the device's hardware, so a session cookie stole
- GlossaryID Token
A JWT issued by an OpenID Connect provider that conveys authentication claims about the user. Unlike access tokens, ID tokens are intended for the client, not f
- GlossaryRefresh Token
A longer-lived credential used to obtain new access tokens without re-authenticating the user. Refresh tokens should be one-time-use (rotated on each exchange)
- BlogA CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later r
- CVECitrix Bleed, session-token leak from NetScaler ADC
A buffer over-read on NetScaler ADC/Gateway leaked session tokens in the clear. Attackers replayed them and skipped the login, including MFA. CISA KEV. October
- TechniqueCross-tenant token confusion
A broker sitting between users and a shared backend fails to keep sessions apart, so a token supplied by one caller gets used to serve a different caller's late