Tag

Security

2026-10-03 · 3 min read

The Token That Cannot Tell You Who Holds It

A bearer token can authorize a request without telling the API which client is making it.

2026-10-03 · 3 min read

From Possession to Proof

DPoP binds an access token to a key and asks the client to sign a fresh description of each request.

2026-10-03 · 3 min read

One Request, Three Checks

A DPoP verifier turns a proof into a decision by checking the key, the request, and the proof's freshness.

2026-10-03 · 3 min read

DPoP in the Industrial Neighborhood

DPoP is one sender-constraint design among bearer tokens, mTLS, platform keys, and custom request signatures.

2026-10-03 · 3 min read

Where the Proof Gets Sharp

DPoP's difficult work lives at boundaries: keys, URLs, clocks, proxies, replay caches, and incomplete support.

2026-10-03 · 3 min read

The Shape of the Tradeoff

DPoP accepts application complexity to make copied tokens less useful across ordinary HTTP deployments.