DPoP-Bound Access Token Request

Security mechanism that allows OAuth clients to bind an access token request to a specific key pair, ensuring the issued token can only be used by the holder of the matching private key.

Security Enhancements

Demonstrating Proof of Possession (DPoP) binds an OAuth 2.0 access token to a public/private key pair held by the client. Instead of a plain bearer token that any party can replay if stolen, with every request, the client proves ownership of the private key corresponding to the public key presented earlier. The authorization server binds this public key to the access token, and resource servers can later verify the same proof-of-possession when the token is used.

This diagram shows the DPoP-bound access token request: the client creates a key pair, builds a DPoP proof JWT, and exchanges an authorization code for an access token that is cryptographically bound to that key.

Authorization ServerClient AppAuthorization ServerClient AppGenerate public/private key pair1Construct DPoP proof JWT2POST /oauth/token3Validate DPoP proof4Issue access token bound to public key5200 OK - DPoP-bound access token6

Official Specifications

Additional Resources

Back to all diagrams