vulns.co
/
GKData.io MCP

Google · 1 min read

Google AIP-158: pagination continuation does not grant resource authority

Google's Approved pagination guidance separates a continuation position from permission to read the collection. Page tokens must be opaque and convey no authorization; each request still requires authorization. Subsequent requests retain the other query arguments, while page size may change. Opacity protects interface abstraction rather than establishing access rights.

Open the reference Implementation GuideReviewed 2026-10-04

How to use this reference

Editorial lesson: document continuation state and actor/resource policy as separate design contracts. An integration following a stored cursor must still rely on the service's per-request authorization decision. Treat query continuity as a request-consistency requirement, not evidence of entitlement.

Before reading

  • Basic familiarity with paginated collection APIs and access-control modeling

Context and limits

  • The page's Created and Updated fields both display 2019-02-18, although its changelog includes 2025-07-08. The linked first-party commit corroborates that later edit; the header is not treated as the current text's last revision date.
  • Query-argument consistency excludes page size: the guidance requires honoring a changed page size and recommends rejecting changes to other arguments. This contract does not establish snapshot isolation or a fixed collection across pages.
  • Opaque token format does not establish permission. This guide supplies no incident, affected-product, bounty, or deployment-specific security claim.

Sources and provenance

  1. AIP-158: Pagination Google · reviewed 2026-10-04
  2. fix(AIP-158): clarify degraded skip response guidance (#1510) Google AIP maintainers · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software