Skip to main content

Command Palette

Search for a command to run...

A service token is not end-user authorization

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

A service-to-service token proves which machine called your API. It does not prove which human may see or change a specific resource.

If an internal worker calls GET /invoices/4821 with a service JWT, that only authenticates the worker. Still authorize the end-user context (or the job’s declared principal) for that invoice: actor, tenant, object, and action.

Otherwise every service credential becomes a master key to every tenant’s data.