Skip to content

Latest commit

 

History

History
26 lines (20 loc) · 630 Bytes

oauth-secure-access-token.md

File metadata and controls

26 lines (20 loc) · 630 Bytes
tags
oauth
security

Mechanism to bind [[oauth-access-token|access_token]] to [[oauth-roles#User Agent|user agent]] from which [[oauth-roles#Application|client]] issued the token. This mechanism resolves issue of stolen [[oauth-bearer-token|Bearer tokens]]

[[tls-mutual-tls|Mutual TLS]]

Working on [[tls]] level

Pros:

  • doesn't require a lot of development team efforts

Cons:

  • hard to deploy
  • requires [[oauth-roles#User|users]] to select certificate to use
  • working on application level

Pros:

  • easy to deploy

Cons:

  • requires development team efforts to implement