Bearer tokens behave like cash
A bearer token works for whoever holds it. It does not care how they got it.
That is the whole risk in one sentence. There is no further check that the holder is the person it was issued to, so a token copied out of a log, a browser or a crash report is as good as the original. It is why they need short lives, careful handling and somewhere to be revoked, and why treating them as merely technical detail goes wrong.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Token scope defines capabilityIt only presses three
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Redirect URI validation protects token deliveryPosted only where it fits
- Token audience prevents universal reuseA ticket for this gate only
