# What Is Token-Based Authentication?

## Metadata
- Author: [[okta.com]]
- Full Title: What Is Token-Based Authentication?
- Category: #articles
- Summary: Token-based authentication gives a user a temporary access token after they verify their identity so they don’t have to re-enter credentials. Tokens can be physical, contactless, or digital (like JWTs) and let admins control access and duration. Tokens improve security and flexibility but require careful implementation and coding knowledge.
- URL: https://www.okta.com/identity-101/what-is-token-based-authentication/
## Highlights
- During the life of the token, users then access the website or app that the token has been issued for, rather than having to re-enter credentials each time they go back to the same webpage, app, or any resource protected with that same token. ([View Highlight](https://read.readwise.io/read/01kd2tq56878y4fp1fd916bf78))
- Auth tokens work like a stamped ticket. The user retains access as long as the token remains valid. Once the user logs out or quits an app, the token is invalidated. ([View Highlight](https://read.readwise.io/read/01m3558zqce8ttz2rebtydwgf4))
- 3 Authentication Token Types
All [authentication tokens](https://www.okta.com/identity-101/security-token/) allow access, but each type works a little differently.
These are three common types of authentication tokens:
• **Connected:** Keys, discs, drives, and other physical items plug into the system for access. If you've ever used a USB device or smartcard to log into a system, you've used a connected token.
• **Contactless:** A device is close enough to a server to communicate with it, but it doesn't plug in. Microsoft's so-called "[magic ringopens in a new tab](https://smallbiztrends.com/2017/07/token-ring-will-replace-passwords.html)" would be an example of this type of token.
• **Disconnected:** A device can communicate with the server across long distances, even if it never touches another device at all. If you've ever used your phone for a two-factor authentication process, you've used this type of token. ([View Highlight](https://read.readwise.io/read/01m355cz63b2b0rerw78saywvr))
- In all three of these scenarios, a user must do something to start the process. They may need to enter a password or answer a question. But even when they complete those preliminary steps perfectly, they can't gain access without the help of an access token. ([View Highlight](https://read.readwise.io/read/01m355dh3c17tyme0z62fd08bk))
- Use a token-based authentication system, and visitors will verify credentials just once. In return, they'll get a token that allows access for a time period you define. ([View Highlight](https://read.readwise.io/read/01m355e16zkxxgrrhcpc9sem6x))
- The process works like this:
• **Request:** The person asks for access to a server or protected resource. That could involve a login with a password, or it could involve some other process you specify.
• **Verification:** The server determines that the person should have access. That could involve checking the password against the username, or it could involve another process you specify.
• **Tokens:** The server communicates with the authentication device, like a ring, key, phone, or similar device. After verification, the server issues a token and passes it to the user.
• **Storage:** The token sits within the user's browser while work continues. ([View Highlight](https://read.readwise.io/read/01m355fvq4ftw7v5xq749ce26d))
- Administrators set limits on tokens. You could allow a one-use token that is immediately destroyed when the person logs out. Or you could set the token to self-destruct at the end of a specified time period. ([View Highlight](https://read.readwise.io/read/01m355g6c3651gfmy56xwmyasq))
- JWTs have three important components.
1. **Header:** Define token type and the signing algorithm involved in this space.
2. **Payload:** Define the token issuer, the expiration of the token, and more in this section.
3. **Signature:** Verify that the message hasn't changed in transit with a secure signature. ([View Highlight](https://read.readwise.io/read/01m355jjzzjbqyn1cf44jd3qjh))
- Authorization tokens are good for administrators of systems that:
• **Often grant temporary access.** Your user base fluctuates based on the date, the time, or a special event. Granting and rescinding access repeatedly is too draining. Tokens could be helpful.
Administrators of university library sites, for example, might appreciate a token approach.
• **Require granular access.** Your server grants access based on specific document properties, not user properties. Passwords don't allow that time of fine-tuned detail.
For example, you run an online journal. You want everyone to read and comment on only one document, not on any others. Tokens could allow this.
• **Are prime hacking targets.** Your server contains sensitive documents that could do your company intense damage on release. A simple password doesn't offer enough protection. A piece of hardware helps quite a bit. ([View Highlight](https://read.readwise.io/read/01m355p8tz60mdq7tykcz44xmn))