What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Require OAuth access tokens on protected resource endpoints—the API operations that read or change protected data. Do not use the access token for those business operations as a credential at /authorize or /token: those are authorization-server endpoints with different jobs. For every protected request, validate the token and authorize the specific action on the specific resource.
Decide by endpoint role, not by URL pattern
An OAuth deployment commonly has both an authorization server and one or more resource servers. The authorization server handles grants, issues tokens, and may manage token status. A resource server uses an access token to decide whether a caller may perform an operation on protected data. An endpoint’s role—not whether its path looks sensitive—determines which credential policy applies.
| Endpoint class | Should it accept the caller’s access token? | Policy |
|---|---|---|
Protected business resources, such as /users, /orders, /files, or domain actions |
Yes, when the data or operation is protected | Validate the token, then authorize its audience/resource, scope, subject, requested action, and relevant context. |
| Public health, discovery, documentation, or login-start routes | Usually no | Leave public only if the data classification and threat model permit it. Do not silently grant broader behavior when an optional token happens to be present. |
Authorization endpoint, such as /authorize |
No, not as the resource credential | Processes authorization requests and the resource-owner interaction; it is not a protected business API. |
Token endpoint, such as /token |
No, not as the token being issued | Processes a grant or refresh request and authenticates the client according to the selected grant; it issues or exchanges tokens. |
| Introspection and revocation endpoints | Provider-specific | Apply the authorization server’s protocol and client-authentication policy; do not assume ordinary end-user bearer-token behavior. |
| JWKS and authorization-server metadata | Usually publicly retrievable | Publish keys or configuration for discovery. They are not general protected resources. |
| Dynamic client registration | Provider-specific | Follow the registration policy and authentication requirements for that authorization server. |
“Usually public” is not a blanket requirement to expose an endpoint: decide based on the data it returns, deployment design, and applicable protocol policy. Similarly, “provider-specific” means the endpoint has its own authentication rules, not that any access token is acceptable.
Do protected endpoints need a token on every request?
For a protected resource operation, yes: the resource server must make an authorization decision for each request. A previously authenticated session, a valid signature, or a token that was accepted on another route does not by itself establish permission for this resource and action. The access token should be restricted to appropriate resources and actions; the server must check that the presented token was meant for the particular resource and operation being requested.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Validate the credential and its intended use
For a JWT access token, verify its signature using trusted issuer keys and validate relevant claims, including issuer, expiration, and audience/resource. If the deployment uses opaque tokens, follow its trusted status-check or introspection mechanism. Do not treat successful cryptographic validation as sufficient authorization.
Authorize the requested action
Check the token’s granted scope or authorization claims against the requested operation, then apply the application’s rules for the subject and current context. For example, a token that permits reading a user’s profile should not automatically authorize changing that profile or reading another user’s data. JWT authorization claims should be considered together with other available contextual information when deciding to allow or reject a call.
- Confirm the token is intended for this API or resource.
- Confirm it has not expired and is valid under the issuer’s rules.
- Confirm the grant covers the operation’s scope and action.
- Apply object-level and contextual policy, such as whether this subject may access this particular record.
Where should clients send the access token?
For bearer tokens, send the credential in the HTTP Authorization header:
GET /v1/orders/123 HTTP/1.1
Host: api.example.com
Authorization: Bearer ACCESS_TOKEN
The resource server should support this header transport. Avoid putting bearer credentials in a URL query string: URLs can be copied into browser history, server logs, analytics, and other systems. Form-body transmission is limited to requests with a defined body and the required content type; it is not the normal choice for API calls.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #2
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Example request shape
Replace the example host, route, and token with values from your own deployment. This illustrates where the bearer credential belongs; it does not obtain a token or establish that the caller is authorized.
curl -i
-H 'Authorization: Bearer ACCESS_TOKEN'
-H 'Accept: application/json'
'https://api.example.com/v1/orders/123'
Should public endpoints accept an optional token?
Usually, no. An endpoint intended to be public should have a clear, documented public policy. Accepting an optional token and silently changing the response or privileges based on it can create ambiguous authorization behavior, caching mistakes, and unexpected access paths.
If a route genuinely needs both anonymous and authenticated behavior, define the two cases explicitly: which data is public, what authenticated callers may additionally see or do, how the token is validated, and how responses are varied or cached. Do not let the mere presence of a token turn a public route into a privileged one without an intentional policy. A separate protected route is often easier to reason about.
Keep OAuth protocol endpoints separate from resource APIs
/authorize: authorization interaction
The authorization endpoint receives authorization-request parameters and conducts the resource-owner authorization interaction. It is not where a client presents the access token intended for a business API. The details of the authorization request and client behavior depend on the OAuth flow in use.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
/token: grant exchange and issuance
The token endpoint processes a grant or refresh request, applies the authorization server’s client-authentication rules for that grant, and issues or exchanges tokens. A bearer access token meant for a resource server is not a substitute for the token endpoint’s required client or grant credentials.
Introspection, revocation, metadata, and registration
These are protocol or authorization-server functions, not ordinary business resources. Introspection and revocation use the server’s defined client-authentication policy. JWKS and authorization-server metadata are commonly published for discovery and key retrieval. Dynamic client registration follows the authorization server’s registration policy. Determine each endpoint’s policy from the relevant server and protocol configuration rather than applying the resource API’s bearer-token rule to all routes.
Handle missing and invalid credentials safely
For protected resources, distinguish authentication failure from authorization failure in the protocol-appropriate response. When a bearer credential is missing or unusable, return an RFC 6750-style WWW-Authenticate challenge with an appropriate error. Avoid revealing whether a protected resource exists when the caller is not authorized to know.
- Do not accept an expired, malformed, untrusted, or wrong-audience token as valid.
- Do not disclose sensitive token-validation details in an error response.
- Make responses consistent across routes so callers can distinguish a missing credential from a denied action without learning protected resource existence.
- Log enough diagnostic context for operators while ensuring logs do not expose bearer-token values.
Implementation checklist
- Classify each route as a protected resource, public route, authorization-server protocol endpoint, or operational endpoint.
- For protected resources, require the access token through the
Authorization: Bearerheader. - Validate token integrity or trusted status, issuer, expiration, and audience/resource on every request.
- Authorize the requested action using scopes or authorization claims plus subject, object-level, and contextual policy.
- Define explicit behavior for anonymous access and optional credentials; do not broaden access implicitly.
- Set separate authentication rules for introspection, revocation, registration, and other authorization-server endpoints.
- Return appropriate challenges and denial responses without disclosing protected-resource existence.
- Consider sender-constrained tokens, such as mutual TLS or DPoP, when the deployment’s risk justifies reducing the usefulness of stolen or leaked tokens.
Common implementation failures and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| A correctly signed token is accepted by the wrong API | The resource server checks signature but not audience/resource. | Validate that the token is intended for this resource, then check action permissions. |
| A read token can change or delete data | Authorization checks only token validity or identity, not action scope. | Map scopes or authorization claims to specific operations and enforce them per request. |
| A public route changes behavior unpredictably for logged-in callers | An optional token is silently changing privileges or response content. | Document and implement the anonymous and authenticated policies explicitly, or separate the routes. |
| Tokens appear in access logs or copied links | The client sends the bearer token in the query string. | Use the Authorization header and review logging behavior for credentials. |
Clients send end-user bearer tokens to /token or /authorize |
Protocol endpoints are being treated as protected business resources. | Separate authorization interaction, grant exchange, and resource access; apply the proper policy to each role. |
| API responses reveal whether an inaccessible record exists | Error behavior differs in a way that exposes protected-resource existence. | Use a consistent denial policy for callers not permitted to know about the resource. |
Or skip the browser setup
For developers whose endpoint work includes capturing web pages, ScreenshotNeo is a separate website screenshot API and MCP server—not an OAuth token endpoint. It uses an API access key in the request shown here; do not mistake this example for an OAuth bearer-token flow. A single GET returns an image or PDF, and you can configure captures for your use case.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #4
- Tamper Resistant Star Key Set Crafted with premium chrome vanadium steel, and each star tool folds neatly into the handle for quick, easy access.
- Details - The handle is engraved with size for quick identification with drilled tips to allow use.
- Portable - Keys fold compact for easy storage, Drilled tips allow use on tamper resistant security screws.
- Size:Full Size T-6, T-7, T-8, T-9, T-10, T-15 T-20, T-25, T-27 and T-30.
- And with 10 total star sizes able to match nearly all standard tamper resistant security screws on the market.
cURL example; replace the target URL and your key:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request options. ScreenshotNeo accepts cookie or consent banners and removes 60+ known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, with response headers identifying the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots.
Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.
Frequently Asked Questions
Can one access token work across multiple APIs?
Only when its audience or resource authorization and the receiving APIs’ policies are designed to permit that use. Each resource server still needs to validate intended audience and action.
Should a health-check endpoint require OAuth?
Not necessarily. Decide whether it exposes protected information or operational capability; a minimal public liveness response may be public, while detailed diagnostics may need protection.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

