# Token, refresh token, and OAuth 2.0 explained

> A token is not a universal password: its permissions, lifetime, and revocation are defined by the service that issued it.

## Access token

An application presents an access token to an API and receives only the permitted actions. Scopes define those permissions; the token may expire or be revoked.

## Refresh token

A refresh token lets an application request a new access token without repeating user consent. It commonly lasts longer and therefore needs stronger storage controls.

## OAuth 2.0

In a normal OAuth flow, the user approves access on the service's official page and the application receives a limited token instead of the password. This is different from transferring a ready-made browser session.

## Discord, X, and Facebook

Use the platform's official OAuth/API, your own registered application, and the minimum scopes for integrations. Automating a normal user account with a ready-made user token may violate platform rules; Discord explicitly disallows self-bots outside its bot/OAuth API.

## Related

- [Account data formats: login, password, 2FA, token, cookie, and JSON](https://getproaccs.com/en/docs/account-data-formats)
- [Cookie, JSON, and Base64: the difference](https://getproaccs.com/en/docs/cookies-json-and-base64)
- [Safe first inspection of a digital account](https://getproaccs.com/en/docs/first-access-security)

## Sources

- [Discord OAuth2](https://docs.discord.com/developers/topics/oauth2)
- [OAuth 2.0 framework](https://www.rfc-editor.org/rfc/rfc6749)

Canonical: https://getproaccs.com/en/docs/tokens-and-oauth
Updated: 2026-10-11
