This document defines a Common Access Token (CAT): a simple, extensible, policy-bearing bearer token for content access. The primary use case for this token is to allow content providers to enforce access policies efficiently, flexibly, and interoperably. This is particularly valuable for audiovisual content access control; however, it is equally beneficial as a general-purpose bearer token for any content type. This token is usable as an OAUTH bearer token, a URI signing token, or more generally as a mechanism for conveying delivery policy.