I have a question to the DPoP spec authors - do you have a suggestion how to approach a token exchange case where the client requests a DPoP token and the submitted subject(actor)_token is / are also DPoP bound?

My first thought was to simply let the client send two DPoP JWTs, one for the submitted token and another for the requested token, and then find a way in the AS to figure out which is which, but then I found this in section 4.3.1:

To validate a DPoP proof, the receiving server MUST ensure that that there is not more than one |DPoP| HTTP request header field,



Vladimir Dzhuvinov

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

OAuth mailing list

Reply via email to