Skip to content

SL1 - Require DPoP? #69

@aaronpk

Description

@aaronpk

The current draft requires that access tokens are sender-constrained using DPoP.

However, the current SL1 draft also says that access tokens are only to be used to retrieve identity claims at the OP (the userinfo endpoint).

Given that access tokens in this profile can't be used to access other resources, does it make sense to drop the DPoP requirement?

Metadata

Metadata

Assignees

Labels

January 2026 InteropExpected to be completed by end of Sept. 2025 for the Jan. 2026 interop.pending closesl1

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions