DPoP Proof Generator
Generate DPoP proofs for sender-constrained tokens (RFC 9449)
Key Pair
{
"crv": "P-256",
"ext": true,
"key_ops": [
"verify"
],
"kty": "EC",
"x": "gODJC-yhIqS3LOvYolqVyx2cn-mlnFVDmtOrF7fbqAk",
"y": "cuPYnZ3Td3wAMBvjKbWfySy530GDdONull4no3QlPiE"
}JWK Thumbprint:
Kt5eSGeKZK8fBPt6Jm_on93P1-_Z_sUaHC5eECYzF8gRequest Details
When calling a resource server, include the access token to generate the ath (access token hash) claim.
If the server returns a DPoP-Nonce header, include it here.
DPoP Proof JWT
Configure request details and click Generate
Usage Example
# Token Request with DPoP POST /token HTTP/1.1 Host: as.example.com Content-Type: application/x-www-form-urlencoded DPoP: <dpop-proof-jwt> grant_type=authorization_code& code=abc123& client_id=my-client # Resource Request with DPoP GET /api/resource HTTP/1.1 Host: rs.example.com Authorization: DPoP <access-token> DPoP: <new-dpop-proof-jwt>
Learn More
About DPoP (RFC 9449)
- •Binds access tokens to a client's cryptographic key pair
- •Prevents token replay attacks even if tokens are stolen
- •Required for FAPI 2.0 compliance in financial applications
- •Alternative to mTLS for sender-constrained token binding
DPoP in IAM
- •FAPI 2.0 – Required for financial-grade API security
- •Mobile Apps – Protect tokens without client secrets
- •SPAs – Browser-based token binding for public clients
- •Zero Trust – Continuous sender verification per request