vulns.co
/
GKData.io MCP
ID / Identity

OAuth, DPoP, and mix-up

Review delegated identity and token flows for strict issuer, client, redirect, audience, and grant binding.

Guide 04 / 154 review notesUpdated 2026-10-11

The review

What to look for

Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.

  1. Map each binding

    Document issuer, client, redirect destination, state, nonce, code verifier, audience, and subject binding for the intended flow.

  2. Review callback decisions

    Confirm successful and error responses apply the same registered redirect and state validation.

  3. Review token acceptance

    Ensure the relying service validates issuer, audience, signature, expiry, and the grant context before account mapping.

  4. Check renewal boundaries

    Confirm refreshed authority stays within the original approved resource and consent scope.

What to produce

  • Grant binding map
  • Callback validation checklist
  • Token validation contract

Common mistakes

  • Accepting a claim without provenance
  • Validating only success redirects
  • Letting refresh expand resource authority

Continue the study

Reading & source context

Editorial notes above connect these references. Open each record for its original source and review date.

Visual models

Connected disclosures

From the field toolkit

Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.

Next skillGraphQL APIs →