aaronpk
aaronpk
Inspired by a question from @thisismissem.social, I wrote up a document describing how to apply DPoP (RFC9449) to the OAuth Device Flow (RFC8628).

https://datatracker.ietf.org/doc/draft-parecki-oauth-dpop-device-flow/
|
Embed
Progress spinner
arichtman@eigenmagic.net
arichtman@eigenmagic.net

@aaronpk so is the authorization server supposed to validate a client certificate before handing out the access token or is that up to the resource server or does the access token get returned encrypted with the bound public key?

|
Embed
Progress spinner