DPoP-Bound Access Token Usage
Flow for interacting with an API endpoint protected by DPoP, a mechanism that ensures the legitimacy of the access token holder.
Once a client holds a DPoP-bound access token, it must prove possession of the private key again on every call to a resource server — the proof created for the token request cannot be reused. Each API call requires a brand-new DPoP proof JWT, scoped to that specific request's HTTP method and URL, with a fresh jti and iat.
This diagram shows how the client presents a DPoP-bound access token to a resource server, and how the resource server validates both the token and the accompanying proof before releasing the protected resource. A stolen access token alone is useless to an attacker: without the matching private key, they cannot produce a valid DPoP proof.