DPoP-Bound Access Token Usage

Flow for interacting with an API endpoint protected by DPoP, a mechanism that ensures the legitimacy of the access token holder.

Security Enhancements

Once a client holds a DPoP-bound access token, it must prove possession of the private key again on every call to a resource server — the proof created for the token request cannot be reused. Each API call requires a brand-new DPoP proof JWT, scoped to that specific request's HTTP method and URL, with a fresh jti and iat.

This diagram shows how the client presents a DPoP-bound access token to a resource server, and how the resource server validates both the token and the accompanying proof before releasing the protected resource. A stolen access token alone is useless to an attacker: without the matching private key, they cannot produce a valid DPoP proof.

Resource ServerClient AppResource ServerClient AppCreate new DPoP proof JWT1GET /protectedresource2Validate DPoP proof JWT3Standard token validation4200 OK - Protected resource5

Official Specifications

Additional Resources

Back to all diagrams