Authentication and security

DPoP

An OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.

Demonstrating Proof of Possession, or DPoP, defined in RFC 9449, is an OAuth mechanism for sender-constraining tokens at the application layer. The client holds a private key and sends a signed proof with each request, and the authorisation server binds issued tokens to the matching public key, so a resource server can reject a token presented without a valid proof. It suits agents that run in environments where mutual TLS is impractical.

Agent Minute explains this term on 6 December 2026.

Related terms