Token audience prevents universal reuse
A token should state which service it is for, so it cannot be presented somewhere else.
Without an audience, a token obtained legitimately by one service can be replayed against another that trusts the same issuer. Checking the audience on receipt is a one-line validation that is regularly omitted, and it turns a narrow credential into a general one.
More on OAuth and federation
- OAuth consent is not proof of identityThe ticket, not the person
- Token scope defines capabilityIt only presses three
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Redirect URI validation protects token deliveryPosted only where it fits
