Authorization: Bearer <token> means "whoever bears this token gets access." The client logs in once, receives a token, and sends it with each request. Tokens can carry scopes and expire, decoupling the credential from the password. Most modern APIs (OAuth, JWT-based) use bearer tokens — protect them like passwords.