Skip to content

[ABCA] Implement Refresh Token Binding #201

@Awambeng

Description

@Awambeng

Description

This is a proxy of:

Bind refresh tokens to the client instance key used for attestation.

Potential considerations

  • On token issuance, bind refresh token to cnf.jwk public key
  • On refresh request, verify the same key is used
  • Reject refresh requests from mismatched keys with invalid_client_attestation
  • Ensure PoP + Attestation validation applies to refresh flows
  • Add necessary fields to token/session model

estimated time: 2–3 days

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions