The working group explicitly decided that a different name should be used, to 
make it clear that other token types other than bearer tokens could also be 
used with OAuth 2.

                                                            -- Mike

From: [] On Behalf Of Doug 
Sent: Wednesday, May 11, 2011 10:09 PM
Subject: [OAUTH-WG] consistency of token param name in bearer token type

This may have come up before so I'm sorry if I'm repeating. Why does bearer 
token spec introduce a new name for oauth2 access tokens [1], "bearer_token", 
and before that [2], "oauth_token"?

I apologize if this may sound shallow but, why introduce a new parameter name 
verses sticking with what the general oauth2 spec already defines, 
"access_token". It seems arbitrary for an auth server to hand a client an apple 
then have the client hand it off to the resource server and call it an orange.

Was this just for the sake of differentiating the parameter name enough so that 
the bearer tokens may be used in other protocols without being confused with 
oauth2 access_tokens?


-Doug Tangren
OAuth mailing list

Reply via email to