Tag
OAuth
2026-10-03 · 3 min read
The Token That Cannot Tell You Who Holds It
A bearer token can authorize a request without telling the API which client is making it.
2026-10-03 · 3 min readFrom Possession to Proof
DPoP binds an access token to a key and asks the client to sign a fresh description of each request.
2026-10-03 · 3 min readOne Request, Three Checks
A DPoP verifier turns a proof into a decision by checking the key, the request, and the proof's freshness.
2026-10-03 · 3 min readDPoP in the Industrial Neighborhood
DPoP is one sender-constraint design among bearer tokens, mTLS, platform keys, and custom request signatures.
2026-10-03 · 3 min readWhere the Proof Gets Sharp
DPoP's difficult work lives at boundaries: keys, URLs, clocks, proxies, replay caches, and incomplete support.
2026-10-03 · 3 min readThe Shape of the Tradeoff
DPoP accepts application complexity to make copied tokens less useful across ordinary HTTP deployments.