Skip to content

Conversation

@panva
Copy link
Member

@panva panva commented Jul 12, 2025

The draft has a lot to say about utilizing iat and jti for replay detection, to that end the iat must be present.

closes #133

Copy link
Member

@c2bo c2bo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, especially with the removal of exp, mandating iat seems like a good idea.

Co-authored-by: Christian Bormann <[email protected]>
@c2bo c2bo merged commit bfb8948 into oauth-wg:main Jul 16, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pop iat should now be required

4 participants