Skip to main content

Command Palette

Search for a command to run...

Scope tokens to the action, not the identity

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

A common API-key mistake is issuing a token that means “this user” and then letting every endpoint decide what that implies.

Prefer tokens scoped to the action you intend: read invoices for tenant X, create deployments in project Y, rotate secrets for service Z. When the token is presented, authorization checks the declared scope first — before any role lookup that might expand privileges later.

Identity still matters for audit (who asked), but the blast radius of a leaked token should be the scopes on that credential, not every permission that identity holds in the admin console.

If you need a broader capability temporarily, mint a short-lived scoped token instead of widening the long-lived one.