freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #34 of 45

bearer tokens · the standard

RestaVSThe 401 Bandit
Resta saysBearer tokens are the standard: present a token that grants access, no password per request.

Authorization: Bearer <token> means "whoever bears this token gets access." The client logs in once, receives a token, and sends it with each request. Tokens can carry scopes and expire, decoupling the credential from the password. Most modern APIs (OAuth, JWT-based) use bearer tokens — protect them like passwords.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleTrace the lifecycle: login → receive token → use it → expiry.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>POST /login → { token: "eyJ..." }
GET /me
Authorization: Bearer eyJ...   → 200 (until expiry)</pre></body></html>
▶ Open the interactive comic issue
‹ Basic Auth · The Legacy HeaderOauth 2.0 · Delegated Access ›