# auth.bearer-token `parseBearerToken("Bearer eyJhbGciOi...")` is `"eyJhbGciOi..."`. An API calls it with the request's `Authorization` header (or null when there is none) and answers 401 when the result is null; it never throws, because a bad header is the client's mistake and gets an answer, not a crash. It follows RFC 6750 section 2.1: the scheme `Bearer`, one or more spaces, then a `b64token`, which is letters, digits and `- . _ ~ + /`, optionally followed by `=` padding. The scheme is case-insensitive (`bearer`, `BEARER`), as HTTP authentication schemes are (RFC 9110 section 11.1). Spaces and tabs around the whole value are ignored, since HTTP strips them from field values anyway. Everything else is null: another scheme (`Basic ...`), `Bearer` with no token, a space or a tab inside the token, `=` anywhere but the end, non-ASCII characters, or `Bearerabc` with no separating space. A JWT (three base64url parts joined by dots) is always a valid `b64token`. This only finds the token; checking it is `auth.jwt` (or `auth.access-token`, which does both). Source: RFC 6750, The OAuth 2.0 Authorization Framework: Bearer Token Usage, section 2.1 (https://www.rfc-editor.org/rfc/rfc6750#section-2.1).