Skip to content

DPoP #1050

@dagframstad

Description

@dagframstad

I need to validate DPoP access tokens in krakend. krakend fails to get the access token if the Authorization header starts with DPoP, it expects Bearer.
And if krakand also could validate the proof of possession in the DPoP header so we don't have to do that in the backend it would be even better, but at the very least let the request pass if it is using a DPoP access token with all the expected scopes and audience.

Are there any plans to support DPoP?

krakend-ce version 2.12.0.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions