Skip to content
Skip to main content
Cloud Services Technical Explainer

What is a token event in a cloud log?

A token event records part of the lifecycle of a digital credential that lets a session, device or application access a cloud service without sending the password with every request. Issue, refresh, use and revocation events can explain how access continued - and why a password reset did not necessarily end it.

Tokens separate authentication from later access

After an interactive login, a service commonly issues a short-lived access token and may issue a longer-lived refresh token that obtains replacements. Applications and service accounts can also receive tokens without a person signing in at that moment.

Capture the provider's token type and event definition, account or principal, application/client ID, session ID, issue and expiry times, source address, device information, result and correlation values. Full token secrets are normally absent from logs; identifiers or hashes may be available instead and must not be mistaken for the token itself.

Follow the whole lifecycle

A token issued legitimately can later be replayed from another device or network. Compare issue and refresh records with login, application-consent, session and API activity. A token-use event is not a fresh login and does not by itself prove who possessed the token.

Password change, session revocation and token revocation can have different effects. Confirm which token family or sessions were invalidated and when access actually failed or expired.

Session identifiers connect activity within a provider session; API events show requests made with the resulting authority.

The point to remember

Token events show how authority was issued and carried forward. Reconstruct issue, refresh, use, expiry and revocation before treating continued access as a new login.

Reference: CLD-121Cloud Services