Markdown Version | Session Recording

Session Date/Time: 20 Jan 2025 17:00

OAUTH

Summary

Dmitri from Back Bay UK presented a proposal for "single-use tokens" within the OAUTH framework. The concept aims to standardize the handling of tokens that are intended for a single consumption, such as those used for high-value transactions like payments, or for internal authorization server needs like magic links and password resets. The discussion focused on the technical challenges of enforcing single-use at scale and the overlap with existing OAUTH mechanisms like DPoP and Rich Authorization Requests (RAr).

Key Discussion Points

Next Steps

Dmitri will continue to refine the draft based on the feedback received during the session, particularly regarding the nuances of enforcing "one-time use" at scale and the interplay with existing OAUTH specifications. The next interim session will discuss private key JOT issues.