Series · 6 parts
Proof-Carrying HTTP: Understanding DPoP
1
The Token That Cannot Tell You Who Holds ItA bearer token can authorize a request without telling the API which client is making it.
2
From Possession to ProofDPoP binds an access token to a key and asks the client to sign a fresh description of each request.
3
One Request, Three ChecksA DPoP verifier turns a proof into a decision by checking the key, the request, and the proof's freshness.
4
DPoP in the Industrial NeighborhoodDPoP is one sender-constraint design among bearer tokens, mTLS, platform keys, and custom request signatures.
5
Where the Proof Gets SharpDPoP's difficult work lives at boundaries: keys, URLs, clocks, proxies, replay caches, and incomplete support.
6
The Shape of the TradeoffDPoP accepts application complexity to make copied tokens less useful across ordinary HTTP deployments.