Access token
A credential a client presents to access protected resources, representing a specific, limited authorisation.
In OAuth 2.0, an access token is a credential used to access protected resources, representing an authorisation issued to the client with a specific scope and lifetime. Most tokens are bearer tokens, meaning any party in possession of one can use it, so they must be protected in transit and at rest. For agents, short-lived tokens bound to the client that requested them limit the damage if a token is copied or leaked.
Agent Minute explains this term on 22 November 2026.
Related terms
OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.OAuth scopeA value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.DPoPAn OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.Mandate expiryThe point after which a mandate no longer authorises anything, as a fixed end time or on completion of a task.