Paul: it sounds like you are proposing this draft replace DPoP, at least
for some use cases — is that correct?

On Tue, Sep 22, 2026 at 3:43 PM Paul Bastian <[email protected]> wrote:

> I support the adoption.
>
> We have a stable HTTP message signature specification now and people
> deploying DPoP have realized a number of shortcomings that Christian and I
> presented about at the OAuth Security workshop last time.
>
> Paul
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to