@techreport{parecki-oauth-jwt-dpop-grant-01, number = {draft-parecki-oauth-jwt-dpop-grant-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-parecki-oauth-jwt-dpop-grant/01/}, author = {Aaron Parecki}, title = {{OAuth 2.0 JWT Authorization Grant with DPoP Binding}}, pagetotal = 7, year = 2026, month = jan, day = 30, abstract = {This specification defines a new OAuth 2.0 authorization grant type that uses a JSON Web Token (JWT) assertion to request an access token that is bound to a specific key using the Demonstration of Proof-of- Possession (DPoP) mechanism. This provides a higher level of security than a simple bearer token, as the client must prove possession of the key to use the access token.}, }