%% You should probably cite rfc7800 instead of this I-D. @techreport{ietf-oauth-proof-of-possession-11, number = {draft-ietf-oauth-proof-of-possession-11}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-oauth-proof-of-possession/11/}, author = {Michael B. Jones and John Bradley and Hannes Tschofenig}, title = {{Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)}}, pagetotal = 15, year = 2015, month = dec, day = 18, abstract = {This specification describes how to declare in a JSON Web Token (JWT) that the presenter of the JWT possesses a particular proof-of- possession key and how the recipient can cryptographically confirm proof of possession of the key by the presenter. Being able to prove possession of a key is also sometimes described as the presenter being a holder-of-key.}, }