« All Articles
IETF RFC
2019-07-08

OAuth 2.0 Demonstration of Proof-of-Possession at the Application Layer

Abstract: This document describes a mechanism for sender-constraining OAuth 2.0 tokens via a proof-of-possession mechanism on the application level. This mechanism allows for the detection of replay attacks with access and refresh tokens.