Security › Authentication & Authorization
Bearer Token
A token that grants access to whoever presents it, sent in the Authorization header.
“Bearer” means whoever bears (holds) this token gets access, no further proof needed. Like cash: if someone steals it, they can spend it.
It’s sent in the Authorization header:
GET /api/orders HTTP/1.1
Authorization: Bearer eyJhbGciOiJIUzI1NiJ9...
The token itself can be a JWT or an opaque random string the server looks up. “Bearer” describes how it’s used, not what’s inside.
Consequences
- Always use HTTPS, or anyone on the network can copy the token.
- Never put tokens in URLs (
?token=...). URLs end up in server logs, browser history, andRefererheaders. - Never log the
Authorizationheader. Check what your request logging middleware records. - Keep them short-lived, so a leaked token stops working soon.