Learning path

Full curriculum

Full curriculum

Unit content

Bearer credentials, expiry and revocation

A bearer credential grants authority to whoever presents it. Examples include session identifiers, API tokens and some access tokens.

The verifier does not need to know who physically holds the credential; possession is the proof. A leaked bearer token can therefore be replayed by another party until some other control stops it.

A secure bearer credential should normally be

  • difficult to guess;
  • transmitted and stored through channels appropriate to its sensitivity;
  • limited in scope where possible;
  • given an expiry appropriate to its use;
  • revocable when compromise or logout requires invalidation.

Short lifetimes reduce the useful window after leakage, while revocation lets the issuer invalidate a credential before its natural expiry.

Bearer credentials should not be confused with identifiers. A public account ID can name a principal; a bearer token carries authority to act.