# A service token is not end-user authorization

A service-to-service token proves which machine called your API. It does not prove which human may see or change a specific resource.

If an internal worker calls `GET /invoices/4821` with a service JWT, that only authenticates the worker. Still authorize the end-user context (or the job’s declared principal) for that invoice: actor, tenant, object, and action.

Otherwise every service credential becomes a master key to every tenant’s data.
