About 107,000 results
Open links in new tab
  1. authentication - Why is 'Bearer' required before the token in ...

    Dec 21, 2015 · What exactly is the difference between following two headers: Authorization : Bearer cn389ncoiwuencr vs Authorization : cn389ncoiwuencr All the sources which I have …

  2. oauth - JWT-bearer grant with JWT assertion vs. client credentials ...

    Jan 14, 2025 · Note that the JWT bearer token doesn't contain the client credentials and may have to be combined with client authentication. For example, in the Microsoft On-Behalf-Of …

  3. Will "Authorization: Bearer" in request header fix CSRF attacks?

    Nov 1, 2017 · Would this approach actually work to prevent CSRF attacks? Yes. An attacker can't make a browser send a request that includes the authorization header with the correct bearer …

  4. What are the alternatives for a bearer token mechanism?

    Oct 14, 2019 · Who gets a bearer token, will have all the privileges of the actual owner of the token. Is there any tokening mechanism which is not suffering from this issue?

  5. Multiple "Bearer" keywords in single Authorization header

    Nov 9, 2020 · I have recently seen a web application that, while using Authorization header, accepted multiple Bearer keywords followed by a valid JWT token. For example, all of the …

  6. CORS request is not sending Authorization: Bearer <value> header

    Jan 9, 2022 · Bearer tokens are not sent automatically. They must be manually added by the client on every request. As such, any site that uses bearer tokens as its only form of session …

  7. Do I need CSRF token if I'm using Bearer JWT?

    Sep 29, 2017 · Bearer tokens, or other HTTP header based tokens that need to be added manually, would prevent you from CSRF. Of course, but sort of off-topic, if you have a XSS …

  8. Does a web access token need to be encoded?

    Mar 8, 2023 · Ah you didn't mention in the question that the token is supposed to be shared! Usually that is the exact opposite of something you want for a token! I'm kind of confused what …

  9. OIDC with JWT in HTTP-only cookie instead of HTTP Authorization …

    Dec 11, 2023 · I'm exploring the possibility of implementing OpenID Connect (OIDC) with an HTTP-only cookie to keep my frontend code completely authentication-agnostic, instead of …

  10. cookies - OAuth access token vs session key - Information Security ...

    Sep 16, 2012 · OAuth Bearer tokens are a little different. These tokens are usually managed by the client (JavaScript, Flash, or even some middleware application). If your application uses …