---
term: "DPoP"
category: "Authentication and security"
url: https://agenticopenfinance.com/glossary/dpop
source: AgenticOpenFinance glossary
---

# DPoP

> An OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.

Demonstrating Proof of Possession, or DPoP, defined in RFC 9449, is an OAuth mechanism for sender-constraining tokens at the application layer. The client holds a private key and sends a signed proof with each request, and the authorisation server binds issued tokens to the matching public key, so a resource server can reject a token presented without a valid proof. It suits agents that run in environments where mutual TLS is impractical.

Related terms: [Access token](https://agenticopenfinance.com/glossary/access-token.md), [FAPI 2.0 Security Profile](https://agenticopenfinance.com/glossary/fapi-2.md), [HTTP Message Signatures](https://agenticopenfinance.com/glossary/http-message-signatures.md), [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md)
