DPoP
An OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.
Demonstrating Proof of Possession, or DPoP, defined in RFC 9449, is an OAuth mechanism for sender-constraining tokens at the application layer. The client holds a private key and sends a signed proof with each request, and the authorisation server binds issued tokens to the matching public key, so a resource server can reject a token presented without a valid proof. It suits agents that run in environments where mutual TLS is impractical.
Agent Minute explains this term on 6 December 2026.
Related terms
Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.FAPI 2.0 Security ProfileAn OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.HTTP Message SignaturesAn IETF standard for signing selected parts of an HTTP request or response so the receiver can verify them.OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.