Validate whether a token is valid for this API and this action.
An internal admin API accepts any JWT signed by the company identity provider. A staging token with audience mobile-app successfully deletes a production feature flag. API security gets confused when teams collapse identity, delegation, and permission into one word: auth. Authentication asks who the subject is. Authorization asks what that subject or client may do. OAuth 2.0 is primarily an authorization framework: it lets a client obtain an access token to call a protected resource, often without sharing the resource owner credentials. That token is not a magic user profile and not a permanent session. The API still has to…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in