A bearer token replaces the session's record with a signature. curl sends the password once, to /login, inside TLS. The server answers with a token: the claims (who, which role, until when, for which services), signed with the server's private key. curl sends the token with every request, as Authorization: Bearer …
Read More