A token handed to an application after sign-in that confirms the user was authenticated and carries details about who they are. Calling an API needs a separate access token, which is about authorisation.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains ID token in context, with comparison tables and the common traps.
Terms in this definition
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Access token
A credential an application hands to an API or other resource to prove what it has been authorised to do for a signed-in user. It deals with permissions, unlike the ID token, which records the sign-in itself.
- Authorisation
Working out which actions and data a signed-in user or application is permitted, typically via role assignments. It comes after authentication.