---
title: "ID tokens and access tokens in OIDC"
description: "How can you distinguish proof of sign-in from permission to call an API?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T04.04/"
topicId: "T04.04"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

How can you distinguish proof of sign-in from permission to call an API?

## What we will work through

Distinguish proof of sign-in from permission to call an API.

## Before you begin

Previously covered: OAuth participants and delegated access; Inside a JWT: header, payload, and signature.

- [OAuth participants and delegated access](/en/articles/topics/T04.01/)
- [Inside a JWT: header, payload, and signature](/en/articles/topics/T03.01/)
