What is a token-based authentication event?¶
A token-based authentication event records a service accepting or processing a token that represents an identity and permissions. The token may derive from an earlier login and be presented automatically without fresh human input.
Tokens represent several kinds of access¶
They can carry a browser session, delegated application authority, mobile-app access or a service identity. Records may identify the account, client, token type, scopes, device, source, result and whether the event was issue, validation, refresh or reuse.
Those fields establish the credential the service trusted. They do not show who possessed it: tokens can remain on a device, be copied or stolen, and sometimes survive a password change until expiry or revocation.
Reconstruct issue, use and revocation¶
Link token events to the originating sign-in, client application, session, device and later resource activity. Establish validity period, granted scopes and the provider's revocation rules. Preserve identifiers and metadata without unnecessarily copying a live bearer token.
Report that the service accepted a token for the represented identity. Personal login, legitimate control and fresh user presence are separate conclusions requiring additional evidence.
The point to remember
A token event shows acceptance of a technical credential, not necessarily a fresh login or the person controlling it.