Bearer tokens behave like cash

A bearer token works for whoever holds it. It does not care how they got it.

That is the whole risk in one sentence. There is no further check that the holder is the person it was issued to, so a token copied out of a log, a browser or a crash report is as good as the original. It is why they need short lives, careful handling and somewhere to be revoked, and why treating them as merely technical detail goes wrong.

More on OAuth and federation