Bearer token

A token that grants access to whoever holds it, with no further proof of identity or key possession; OAuth access tokens are commonly used this way, so a stolen one works for the thief.

A bearer token is a security token that any party holding it can use, in the same way as any other holder could. RFC 6750, the OAuth 2.0 bearer token usage specification, defines the property: using the token does not require the bearer to prove possession of any cryptographic key. The token is the whole credential, which is why it is often compared to cash. OAuth access tokens are commonly sent as bearer tokens, and a session cookie that stands alone behaves the same way.

If a bearer token is copied from a log, a browser, a URL or intercepted traffic, the copy works for the attacker until it expires or is revoked. Controls therefore include sending tokens only over TLS, keeping lifetimes short, narrowing scope and audience, and keeping them out of URLs. Later specifications define sender-constrained tokens, bound to a key the client must prove it holds, so that a stolen token alone is not enough. A JSON Web Token is a format, so a JWT may or may not be used as a bearer token.

Exam relevance: a scenario is likely to describe a stolen token being replayed from another device. Candidates are expected to recognise the bearer property as the weakness, and to choose short lifetimes, protected transport or proof-of-possession binding as the mitigation.