---
title: "Token"
description: "the claims of an access token; the gateway checks six of them and grants nothing on the token alone"
section: concepts
address: /concepts/token
contract: 0476e35e6e275db5
---

# Token

the claims of an access token; the gateway checks six of them and grants nothing on the token alone

[figure: Token is a value at none scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | value |
| scope | none |
| key | none |
| store | none |
| family | people |



## Fields


| field | type | required | note |
|---|---|---|---|
| `token_use` | `one of access` | yes | it is marked as an access token |
| `subject` | `text` | yes |  |
| `issuer` | `address` | yes |  |
| `client` | `id` | yes | which client it was given to |
| `audience` | `text` | yes | which service it is made out to |
| `expires_at` | `time` | yes |  |
| `signed_in_strength` | `text` | no |  |
| `signed_in_at` | `time` | no |  |
| `access_scopes` | [AccessScope](/concepts/accessscope) | yes |  |
| `acting_for` | `[text]` | no | outermost first |
| `bound_key` | `hash` | no | the holder's key it is tied to |



## Routes that use it
No route takes or returns Token directly. The record holds it, and the objects that point at it reach it.
