Skip to content
>devspeak
← glossary
level 5APIs & Communication

Token

also: access token, api token, bearer token, jwt, refresh token, auth token

A long secret string that proves you're allowed in, so you don't send your password with every request. Think of it as a temporary pass.

a bit more technical

A credential string issued after authentication, or generated for API access, and sent with each request, often as an "Authorization: Bearer ..." header. Access tokens usually expire quickly; refresh tokens get new ones. A JWT is a token carrying signed data the server can verify.

picture it

A festival wristband. You show ID once at the gate, then flash the wristband at every stage. It expires at the end of the weekend, and anyone who steals it can get in.

why it matters

Tokens keep users logged in and let your app talk to services like Stripe or OpenAI. They're also secrets: a leaked token lets someone act as you until it expires or is revoked.

what your agent might say
agent
The requests fail after an hour because the access token expires, and we never use the refresh token to get a new one.
how you might use it
you → your agent
Store the API token in an environment variable, never in the code, and make sure it's never sent to the browser.
common mistake

Treating a token as harmless because it isn't a password. Anyone holding a valid token can usually do whatever it allows.