Specification and maturity
- Category
- proof of possession
- Version
- RFC 9449
- Status from supplied research
- IETF RFC as cited by supplied research; external text not packaged locally
- Status verification
- SOURCE_NOT_LOCALLY_AVAILABLE
- Source class
- external IETF security specification
- Implementation maturity
- No DPoP client or resource-server validation in Eviulon.com
- Eviulon use class
- SUPPORTED_CONCEPT
- Review date
- 2026-08-08
Privacy and authority
Privacy effect: Sender-constraining tokens can reduce replay but key reuse may create correlation if profiles are not purpose-bound.
Authority boundary: Proof of possession shows control of a key; it does not establish who the legal actor is or what the actor may do.
Dependencies
- OAuth token service
- key management
- nonce handling
- HTTP method/URI binding
Risks
- key reuse
- clock skew
- nonce handling errors
- proxy normalization
Evidence and truth boundary
Descriptive standards map only. A record does not prove Patefacere adoption, Eviulon legal adoption, interoperability, conformance, passport issuance, credential presentation, live revocation, production trust anchors, or external recognition. External specification status is recorded as source-derived and review-due unless the specification is packaged locally.
Authority and record status
Responsible authority: external IETF security specification.
Source-derived status remains externally unverified unless packaged locally.
Revision date: . Public corrections may be initiated through the diplomatic contact route.