DPoP-Bound Access Token Request
Security mechanism that allows OAuth clients to bind an access token request to a specific key pair, ensuring the issued token can only be used by the holder of the matching private key.
Demonstrating Proof of Possession (DPoP) binds an OAuth 2.0 access token to a public/private key pair held by the client. Instead of a plain bearer token that any party can replay if stolen, with every request, the client proves ownership of the private key corresponding to the public key presented earlier. The authorization server binds this public key to the access token, and resource servers can later verify the same proof-of-possession when the token is used.
This diagram shows the DPoP-bound access token request: the client creates a key pair, builds a DPoP proof JWT, and exchanges an authorization code for an access token that is cryptographically bound to that key.