{
  "slug": "oauth",
  "name": "OAuth, DPoP, and mix-up",
  "category": "Identity",
  "summary": "Review delegated identity and token flows for strict issuer, client, redirect, audience, and grant binding.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Authorization-server metadata",
    "Registered client configuration",
    "Documented callback and token handling"
  ],
  "review": [
    {
      "title": "Map each binding",
      "body": "Document issuer, client, redirect destination, state, nonce, code verifier, audience, and subject binding for the intended flow."
    },
    {
      "title": "Review callback decisions",
      "body": "Confirm successful and error responses apply the same registered redirect and state validation."
    },
    {
      "title": "Review token acceptance",
      "body": "Ensure the relying service validates issuer, audience, signature, expiry, and the grant context before account mapping."
    },
    {
      "title": "Check renewal boundaries",
      "body": "Confirm refreshed authority stays within the original approved resource and consent scope."
    }
  ],
  "outputs": [
    "Grant binding map",
    "Callback validation checklist",
    "Token validation contract"
  ],
  "pitfalls": [
    "Accepting a claim without provenance",
    "Validating only success redirects",
    "Letting refresh expand resource authority"
  ],
  "references": {
    "resources": [
      {
        "id": "rfc-9700-oauth-security-best-current-practice",
        "title": "RFC 9700: Best Current Practice for OAuth 2.0 Security",
        "url": "https://vulns.co/research/resources/rfc-9700-oauth-security-best-current-practice/"
      },
      {
        "id": "rfc-10017-browser-oauth-token-custody",
        "title": "RFC 10017: OAuth 2.0 for Browser-Based Applications",
        "url": "https://vulns.co/research/resources/rfc-10017-browser-oauth-token-custody/"
      },
      {
        "id": "n8n-2026-refresh-grant-resource-binding",
        "title": "n8n: refreshed authority must remain bound to the consented resource",
        "url": "https://vulns.co/research/resources/n8n-2026-refresh-grant-resource-binding/"
      }
    ],
    "diagrams": [
      {
        "id": "identity-claim-binding",
        "title": "An identity claim must belong to the user",
        "url": "https://vulns.co/research/diagrams/identity-claim-binding/"
      },
      {
        "id": "delegated-grant-authority-continuity",
        "title": "Delegated authority stays within the approved grant",
        "url": "https://vulns.co/research/diagrams/delegated-grant-authority-continuity/"
      }
    ],
    "reports": [
      {
        "id": "apple-sign-in-identity-claim-binding-2020",
        "title": "Sign in with Apple failed to bind identity claims to the authenticated user",
        "url": "https://vulns.co/research/reports/apple-sign-in-identity-claim-binding-2020/"
      },
      {
        "id": "github-oauth-method-semantics-2019",
        "title": "GitHub OAuth consent failed across request-method semantics",
        "url": "https://vulns.co/research/reports/github-oauth-method-semantics-2019/"
      },
      {
        "id": "google-device-authorization-client-scope-binding-2026",
        "title": "Google device grants lost client and permission binding",
        "url": "https://vulns.co/research/reports/google-device-authorization-client-scope-binding-2026/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/oauth/",
  "markdown_url": "https://vulns.co/skills/oauth/SKILL.md"
}
