ModestDestiny
Proof-Carrying HTTP: Understanding DPoPPart 1 of 6
2026-10-03 · OAuth
All postsThe Token That Cannot Tell You Who Holds It
A bearer token can authorize a request without telling the API which client is making it.
Proof-Carrying HTTP: Understanding DPoPPart 2 of 6 2026-10-03 · OAuthFrom Possession to Proof
DPoP binds an access token to a key and asks the client to sign a fresh description of each request.
Proof-Carrying HTTP: Understanding DPoPPart 3 of 6 2026-10-03 · OAuthOne Request, Three Checks
A DPoP verifier turns a proof into a decision by checking the key, the request, and the proof's freshness.
Proof-Carrying HTTP: Understanding DPoPPart 4 of 6 2026-10-03 · OAuthDPoP in the Industrial Neighborhood
DPoP is one sender-constraint design among bearer tokens, mTLS, platform keys, and custom request signatures.
Proof-Carrying HTTP: Understanding DPoPPart 5 of 6 2026-10-03 · OAuthWhere the Proof Gets Sharp
DPoP's difficult work lives at boundaries: keys, URLs, clocks, proxies, replay caches, and incomplete support.
Proof-Carrying HTTP: Understanding DPoPPart 6 of 6 2026-10-03 · OAuthThe Shape of the Tradeoff
DPoP accepts application complexity to make copied tokens less useful across ordinary HTTP deployments.