Token audience prevents universal reuse

A token should state which service it is for, so it cannot be presented somewhere else.

Without an audience, a token obtained legitimately by one service can be replayed against another that trusts the same issuer. Checking the audience on receipt is a one-line validation that is regularly omitted, and it turns a narrow credential into a general one.

More on OAuth and federation