Unit content
Bearer credentials, expiry and revocation
A bearer credential grants authority to whoever presents it. Examples include session identifiers, API tokens and some access tokens.
The verifier does not need to know who physically holds the credential; possession is the proof. A leaked bearer token can therefore be replayed by another party until some other control stops it.
A secure bearer credential should normally be
- difficult to guess;
- transmitted and stored through channels appropriate to its sensitivity;
- limited in scope where possible;
- given an expiry appropriate to its use;
- revocable when compromise or logout requires invalidation.
Short lifetimes reduce the useful window after leakage, while revocation lets the issuer invalidate a credential before its natural expiry.
Bearer credentials should not be confused with identifiers. A public account ID can name a principal; a bearer token carries authority to act.