Skip to content

Verify DPoP Proof public key during refresh_token grant for public clients #1949

Closed
@jgrandja

Description

@jgrandja

For public clients during the refresh_token grant flow, the DPoP Proof PublicKey must be the same as the access token PublicKey binding.

Related gh-1813

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions