Skip to content

Internet Draft: OAuth 2.0 Demonstration of Proof-of-Possession at the Application-layer

Notifications You must be signed in to change notification settings

danielfett/draft-dpop

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 

Repository files navigation

OAuth 2.0 Demonstration of Proof-of-Possession at the Application Layer

This document defines an application-level sender-constraint mechanism for OAuth 2.0 access tokens and refresh tokens that can be applied when neither mTLS nor OAuth Token Binding are utilized. It achieves proof-of-possession using a public/private key pair.

Written in markdown for the mmark processor.

Compiling

using Docker

From the root of this repository, run

docker run -v `pwd`:/data danielfett/markdown2rfc main.md

(see https://github.com/oauthstuff/markdown2rfc)

without Docker

compile using mmark and xml2rfc: mmark main.md > draft.xml; xml2rfc --html draft.xml

About

Internet Draft: OAuth 2.0 Demonstration of Proof-of-Possession at the Application-layer

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published