An HTTP authorization scheme that passes a token in the request's Authorization header (`Authorization: Bearer <token>`) — the dominant pattern for API authentication, including OAuth 2.0 access tokens.
Bearer Tokens are opaque strings that grant access if the holder ('bearer') presents them — no signature required (unlike older schemes like HTTP Basic with credentials hashing). OAuth 2.0 access tokens are bearer tokens, as are most modern API keys. The simplicity is also the risk: anyone who intercepts the token can use it. Bearer tokens MUST be sent over TLS and ideally short-lived (refreshed periodically) to limit damage from leaks.
Authenticating to the GitHub API with `Authorization: Bearer ghp_xxxx` — every request needs the header; no separate login step per call.
Bearer Tokens are the modern API auth default because they're simple to implement and inspect — the right model for stateless HTTP services.
Need help implementing this in your business?
Get Started