What is token theft?¶
Token theft is unauthorised acquisition of a digital token that represents access or authority.
A token may represent a user session, application permission, API access, device identity or the ability to refresh access later.
The important thing is to identify what the token was for and what it allowed.
Token type defines capability¶
Useful questions include:
- who issued it;
- which account/device/app it represented;
- what permissions it carried;
- when it was created;
- where it was stored;
- how long it remained valid;
- whether it could refresh;
- when it was revoked.
A token with read-only application scope means something very different from a refresh token capable of creating new access.
Tokens can come from several places¶
They may exist in:
- browser storage;
- application databases;
- memory;
- configuration files;
- cloud environments;
- logs;
- developer tooling.
That means the theft route may sit on a device, application or cloud platform rather than at the login page.
Finding a token is not proof it was replayed¶
Separate:
Legitimate applications also use tokens automatically, so provider and device context matter.
Check what containment actually invalidated¶
A password reset may not invalidate every token class.
If access continues after reset, compare token refresh and revocation records before concluding the reset “failed”.
The practical point is: explain the token's identity, permissions and lifecycle, then prove unauthorised use through provider and device records rather than token presence alone.