---
term: "Access token"
category: "Authentication and security"
url: https://agenticopenfinance.com/glossary/access-token
source: AgenticOpenFinance glossary
---

# Access token

> A credential a client presents to access protected resources, representing a specific, limited authorisation.

In OAuth 2.0, an access token is a credential used to access protected resources, representing an authorisation issued to the client with a specific scope and lifetime. Most tokens are bearer tokens, meaning any party in possession of one can use it, so they must be protected in transit and at rest. For agents, short-lived tokens bound to the client that requested them limit the damage if a token is copied or leaked.

Related terms: [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md), [OAuth scope](https://agenticopenfinance.com/glossary/oauth-scope.md), [DPoP](https://agenticopenfinance.com/glossary/dpop.md), [Mandate expiry](https://agenticopenfinance.com/glossary/mandate-expiry.md)
