Grants limited access on behalf of a user or in its own right. Bearer tokens are vulnerable because possession is enough; current practice (see RFC 9700, PKCE, token exchange, mTLS-bound tokens, DPoP) narrows, binds and sender-constrains authority.

Terms

Glossary terms used here: Bearer token.