---
title: "DPoP — Identity Glossary | IDSync"
description: "DPoP (Demonstrating Proof-of-Possession, RFC 9449) binds an OAuth access token to a client-held key, so a stolen bearer token cannot be replayed from a…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "DPoP",
          "item": "https://idsync.com/glossary/dpop"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/dpop",
      "name": "DPoP",
      "alternateName": [
        "Demonstrating Proof-of-Possession",
        "RFC 9449"
      ],
      "description": "DPoP (Demonstrating Proof-of-Possession, RFC 9449) binds an OAuth access token to a client-held key, so a stolen bearer token cannot be replayed from a different device or process.",
      "url": "https://idsync.com/glossary/dpop",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is DPoP a replacement for PKCE?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. PKCE protects the authorization code exchange. DPoP protects the access token in use. Use both."
          }
        },
        {
          "@type": "Question",
          "name": "Do all IdPs support DPoP?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Support is growing but uneven. Verify your IdP and resource servers both implement RFC 9449 before designing around it."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  DPoP 

Authentication

# DPoP (Demonstrating Proof-of-Possession)

DPoP (Demonstrating Proof-of-Possession, RFC 9449) binds an OAuth access token to a client-held key, so a stolen bearer token cannot be replayed from a different device or process.

Last reviewed 3 months ago

Key points

-   Defined in RFC 9449
-   Mitigates OAuth token theft and replay
-   Client signs a per-request JWT (DPoP proof) with a private key
-   Lighter-weight alternative to mTLS-bound tokens
-   Adopted by FAPI 2.0 and modern banking APIs

## What it is

DPoP turns a bearer token into a _sender-constrained_ token. Even if an attacker steals the access token, they cannot use it without also stealing the client's private key — which typically lives in the device or browser's secure storage.

## How it works

1.  The client generates a key pair and includes the public key (`jkt` thumbprint) when requesting a token.
2.  On every API request, the client attaches a `DPoP` header — a short-lived JWT signed with the private key, binding the request method, URL, and token hash.
3.  The resource server verifies the DPoP proof and checks that the access token's `cnf.jkt` matches the proof's key.

## When buyers care

-   High-value APIs (banking, payments, healthcare) where token theft is realistic
-   SPAs and mobile apps where mTLS is impractical
-   Compliance with FAPI 2.0 / Open Banking profiles

## Common misconceptions

-   **DPoP is not encryption.** It's proof-of-possession; the token itself is still readable.
-   **DPoP and mTLS solve the same problem differently.** Pick mTLS for service-to-service, DPoP for browsers and mobile.

## FAQ

### Is DPoP a replacement for PKCE?

No. PKCE protects the authorization code exchange. DPoP protects the access token in use. Use both.

### Do all IdPs support DPoP?

Support is growing but uneven. Verify your IdP and resource servers both implement RFC 9449 before designing around it.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[sso](/directory/category/sso)[mfa](/directory/category/mfa)[passwordless authentication](/directory/category/passwordless-authentication)

### Vendors to evaluate

[okta](/directory/okta)[auth0](/directory/auth0)[microsoft entra](/directory/microsoft-entra)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the sso category.

[Explore tools](/directory/category/sso)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.