Start with Identity
Concept

Bearer Token

A bearer token is a credential that grants access to whoever presents it, with no proof that the presenter is the party it was issued to. OAuth 2.0 defines how bearer tokens are sent in RFC 6750.

Most OAuth access tokens, browser session cookies and API keys behave as bearer credentials, which is why stealing one is as good as stealing the login: the thief replays it and the server cannot tell the difference. The defenses are to keep bearer tokens short-lived, narrowly scoped and revocable, and, where the risk justifies it, to use sender-constrained tokens that are bound to a key the client must prove it holds, through DPoP (RFC 9449) or mutual TLS (RFC 8705). Bearer credentials also hide in places that do not look like tokens: in September 2026, researchers showed that GitLab's incoming email address works as a non-expiring token that can commit code as its owner.

See also: access token, token theft, session hijacking, token replay on unbound endpoints

Last reviewed By SWI Community TeamSuggest a correctionHow we research