Access token

In OAuth 2.0, the credential a client presents to a resource server to use a protected resource; it represents a granted authorisation, not proof of who the user is.

In OAuth 2.0, an access token is the credential an OAuth client uses to call a protected API. RFC 6749 section 1.4 describes it as a string representing an authorisation issued to the client, carrying a specific scope and duration of access. The authorization server issues it, and the resource server accepts or rejects it. It can be an opaque reference that the resource server looks up, or a self-contained, signed structure such as a JSON Web Token.

The access token is one of three tokens commonly confused. The refresh token is a longer-lived credential the client uses to obtain new access tokens, and it is meant for the authorization server alone. The ID token comes from OpenID Connect and tells the client who authenticated; the access token tells an API what the client may do. Access tokens are commonly used as bearer tokens, so whoever holds one can use it. That is why they are kept short-lived, restricted in scope, and sent only over protected channels.

Exam relevance: questions in this area tend to turn on purpose. Candidates are expected to recognise that an access token grants delegated access to a resource and does not by itself authenticate the user, and to match each token type to the party that consumes it.