Skip to main content
IAMRoadmapIAMRoadmap

DPoP Proof Generator

Generate DPoP proofs for sender-constrained tokens (RFC 9449)

Key Pair

{
  "crv": "P-256",
  "ext": true,
  "key_ops": [
    "verify"
  ],
  "kty": "EC",
  "x": "gODJC-yhIqS3LOvYolqVyx2cn-mlnFVDmtOrF7fbqAk",
  "y": "cuPYnZ3Td3wAMBvjKbWfySy530GDdONull4no3QlPiE"
}
JWK Thumbprint:Kt5eSGeKZK8fBPt6Jm_on93P1-_Z_sUaHC5eECYzF8g

Request Details

When calling a resource server, include the access token to generate the ath (access token hash) claim.

If the server returns a DPoP-Nonce header, include it here.

DPoP Proof JWT

Configure request details and click Generate

Usage Example

# Token Request with DPoP
POST /token HTTP/1.1
Host: as.example.com
Content-Type: application/x-www-form-urlencoded
DPoP: <dpop-proof-jwt>

grant_type=authorization_code&
code=abc123&
client_id=my-client

# Resource Request with DPoP
GET /api/resource HTTP/1.1
Host: rs.example.com
Authorization: DPoP <access-token>
DPoP: <new-dpop-proof-jwt>
Learn More

About DPoP (RFC 9449)

  • •Binds access tokens to a client's cryptographic key pair
  • •Prevents token replay attacks even if tokens are stolen
  • •Required for FAPI 2.0 compliance in financial applications
  • •Alternative to mTLS for sender-constrained token binding

DPoP in IAM

  • •FAPI 2.0 – Required for financial-grade API security
  • •Mobile Apps – Protect tokens without client secrets
  • •SPAs – Browser-based token binding for public clients
  • •Zero Trust – Continuous sender verification per request