Skip to main content

Access Token

An access token is a credential that a client presents to a resource server.

What is Access Token?

An access token is a credential that a client presents to a resource server. It represents an authorization issued to the client, usually with a defined scope and lifetime. It does not prove that the current holder is the original user. Send bearer tokens in the Authorization header over TLS. Do not put bearer tokens in URLs because logs and browser history can expose them.

Why it matters

An access token lets a client call a resource without sending the user's primary credentials. Its audience, scope, lifetime, storage, and transport determine how much harm follows a leak.

How it works

  1. A client completes an authorization grant with an authorization server.
  2. The authorization server issues a token for a defined resource, scope, and lifetime.
  3. The client sends the token to the resource server, which validates it before it authorizes the requested operation.

Example

A command-line client receives a short-lived token for the metrics API with read scope. It sends the token in the Authorization header when it reads one metrics endpoint.

Pomerium boundary

Pomerium can receive bearer tokens on protected HTTP routes. In the default mode, it passes the bearer token to the upstream service without interpreting it. With idp_access_token or idp_identity_token, Pomerium interprets the token as an IdP-issued token and creates a Pomerium session. The selected mode determines whether Pomerium or the upstream service interprets the presented token.

Limits and non-claims

  • A bearer token can be used by any party that obtains it until it expires or is revoked.
  • A token scope does not by itself prove the identity of the current human user.
  • Revocation behavior depends on the token format, authorization server, resource server, and cache design.

Evaluation checklist

  • Does the resource server validate issuer, audience, subject, scope, time, and token type?
  • Is the token a bearer credential or sender-constrained, and where can it leak?
  • Does the target authorize the exact resource and action after token validation?

Sources and further reading

Keep learning

Authorization and Policy

Authorization

Authorization determines whether a subject can perform a requested operation on a resource. It evaluates policy after or alongside authentication.

Learn this term
Identity and AuthenticationAuthorization and Policy

OAuth 2.0

Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.

Learn this term
Application and Service AccessIdentity and Authentication

JSON Web Token (JWT)

Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.

Learn this term
Identity and AuthenticationStandards and Protocols

OpenID Connect (OIDC)

OpenID Connect is an identity layer on top of OAuth 2.0. It lets a client verify an end user's authentication and receive identity claims in an ID token.

Learn this term
Application and Service AccessStandards and Protocols

Signed Header

Pomerium's signed header is the X-Pomerium-Jwt-Assertion header.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo