11 ms·
If a token is not a JWT is it really a “Bearer” token?
by pbreit 1y ago
If a token is not a JWT is it really a “Bearer” token?
- detaro 1y agoyes, 100%
- formerly_proven 1y agoBearer token just means whoever has the token string has the associated capability - like bearer bonds. Unlike e.g. challenge-response or signature authentication.
- unscaled 1y ago"Bearer" and JWT are orthogonal. Tokens in other format or stateful formats can be bearer tokens, while JWTs can use non-bearer authentication methods. For instance, RFC 9449 (DPoP) describes an authentication method where you have to provide a PoP (based on JWS) in addition to an access token (which may or may not be JWT).
- sbergot 1y agoOauth defines bearers tokens without requesting them to be jwt.