Authentication and security

Access token

A credential a client presents to access protected resources, representing a specific, limited authorisation.

In OAuth 2.0, an access token is a credential used to access protected resources, representing an authorisation issued to the client with a specific scope and lifetime. Most tokens are bearer tokens, meaning any party in possession of one can use it, so they must be protected in transit and at rest. For agents, short-lived tokens bound to the client that requested them limit the damage if a token is copied or leaked.

Agent Minute explains this term on 22 November 2026.

Related terms