<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Modest Destiny</title>
  <link href="https://blog.modest-destiny.com" />
  <id>https://blog.modest-destiny.com</id>
  <updated>2026-10-03</updated>
  <generator>Zola 0.23.0</generator>
  
  <entry>
    <title>The Token That Cannot Tell You Who Holds It</title>
    <link href="https://blog.modest-destiny.com/posts/dpop-01-token-cannot-tell/" />
    <id>https://blog.modest-destiny.com/posts/dpop-01-token-cannot-tell/</id>
    <updated>2026-10-03</updated>
    <summary>A bearer token can authorize a request without telling the API which client is making it.</summary>
  </entry>
  
  <entry>
    <title>From Possession to Proof</title>
    <link href="https://blog.modest-destiny.com/posts/dpop-02-from-possession-to-proof/" />
    <id>https://blog.modest-destiny.com/posts/dpop-02-from-possession-to-proof/</id>
    <updated>2026-10-03</updated>
    <summary>DPoP binds an access token to a key and asks the client to sign a fresh description of each request.</summary>
  </entry>
  
  <entry>
    <title>One Request, Three Checks</title>
    <link href="https://blog.modest-destiny.com/posts/dpop-03-one-request-three-checks/" />
    <id>https://blog.modest-destiny.com/posts/dpop-03-one-request-three-checks/</id>
    <updated>2026-10-03</updated>
    <summary>A DPoP verifier turns a proof into a decision by checking the key, the request, and the proof&#39;s freshness.</summary>
  </entry>
  
  <entry>
    <title>DPoP in the Industrial Neighborhood</title>
    <link href="https://blog.modest-destiny.com/posts/dpop-04-industrial-neighborhood/" />
    <id>https://blog.modest-destiny.com/posts/dpop-04-industrial-neighborhood/</id>
    <updated>2026-10-03</updated>
    <summary>DPoP is one sender-constraint design among bearer tokens, mTLS, platform keys, and custom request signatures.</summary>
  </entry>
  
  <entry>
    <title>Where the Proof Gets Sharp</title>
    <link href="https://blog.modest-destiny.com/posts/dpop-05-where-proof-gets-sharp/" />
    <id>https://blog.modest-destiny.com/posts/dpop-05-where-proof-gets-sharp/</id>
    <updated>2026-10-03</updated>
    <summary>DPoP&#39;s difficult work lives at boundaries: keys, URLs, clocks, proxies, replay caches, and incomplete support.</summary>
  </entry>
  
  <entry>
    <title>The Shape of the Tradeoff</title>
    <link href="https://blog.modest-destiny.com/posts/dpop-06-shape-of-tradeoff/" />
    <id>https://blog.modest-destiny.com/posts/dpop-06-shape-of-tradeoff/</id>
    <updated>2026-10-03</updated>
    <summary>DPoP accepts application complexity to make copied tokens less useful across ordinary HTTP deployments.</summary>
  </entry>
  
</feed>
