0Pricing
OAuth2 & OpenID Connect Deep Dive · Lektion

Sendergebundene Tokens mit mTLS

Lernen Sie, wie die Bindung an ein Mutual-TLS-Clientzertifikat Bearer Tokens in sendergebundene Tokens umwandelt und verhindert, dass Angreifer gestohlene Tokens wiederverwenden.

Sendergebundene Tokens mit mTLS ist eine kostenlose OAuth2 & OpenID Connect Deep Dive-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des OAuth2 & OpenID Connect Deep Dive-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der OAuth2 & OpenID Connect Deep Dive-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

The Bearer Token Weakness

A plain bearer token works for anyone who holds it. If it leaks via logs, a proxy, or an XSS bug, the thief can use it freely. Sender-constrained tokens fix this by binding the token to the legitimate client.

What Is mTLS?

Mutual TLS means both sides present certificates: the server proves its identity (as usual) and the client also presents a certificate. The authorization server can then bind issued tokens to that client certificate.

RFC 8705

This is standardized in RFC 8705 (OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens). It covers both client authentication via mTLS and certificate binding of access tokens.

The cnf Claim

When the AS issues a certificate-bound token, it records a confirmation (cnf) claim containing the SHA-256 thumbprint of the client certificate under the key x5t#S256.

{
  "sub": "client-app",
  "cnf": {
    "x5t#S256": "bwcK0esc3ACC3DB2Y5_lESsXE8o9ltc05O89jdN-dg2"
  }
}

Resource Server Check

When the client calls an API over mTLS, the resource server computes the thumbprint of the presented certificate and compares it to the token's cnf.x5t#S256. If they differ, the token is rejected.

thumb = sha256(der_of_client_cert)
if base64url(thumb) != token.cnf['x5t#S256']:
    reject('certificate binding mismatch')

Why a Stolen Token Is Useless

Even with the token, an attacker cannot present the client's private key, so they cannot complete the mTLS handshake with the matching certificate. The thumbprint will not match, and the API rejects them.

mTLS Client Authentication

RFC 8705 also lets clients authenticate at the token endpoint with their certificate instead of a shared secret, using methods tls_client_auth (PKI) or self_signed_tls_client_auth.

mTLS Endpoint Aliases

Because mTLS needs a separate TLS configuration, providers publish mtls_endpoint_aliases in discovery so clients hit the certificate-bound versions of the token and other endpoints.

{
  "mtls_endpoint_aliases": {
    "token_endpoint": "https://mtls.op.example.com/token"
  }
}

mTLS vs DPoP

Both achieve sender-constraint:

  • mTLS — relies on TLS-layer certificates, great for server-to-server and infrastructure with PKI.
  • DPoP — application-layer proof JWTs, better for browser/public clients that cannot manage client certs.

Operational Considerations

mTLS requires certificate provisioning, rotation, and a TLS terminator that forwards the client cert to your app. Plan for cert lifecycle and ensure your reverse proxy passes the verified certificate to the resource server.

When to Adopt It

Choose mTLS-bound tokens for high-assurance, regulated, or financial-grade APIs and trusted backend services where certificate management is feasible. It dramatically raises the cost of token theft.

Quick Check

Test your mTLS binding knowledge.

Recap

mTLS sender-constrained tokens (RFC 8705) bind a token to the client's certificate.

  • The token carries a cnf.x5t#S256 certificate thumbprint.
  • Resource servers match the presented cert's thumbprint; a stolen token without the private key fails.
  • mTLS also enables certificate-based client authentication and uses mtls endpoint aliases.
  • Compare with DPoP for public clients.

Häufig gestellte Fragen

Ist die Lektion „Sendergebundene Tokens mit mTLS“ kostenlos?

Ja — der vollständige Text von „Sendergebundene Tokens mit mTLS“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des OAuth2 & OpenID Connect Deep Dive-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der OAuth2 & OpenID Connect Deep Dive-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Sendergebundene Tokens mit mTLS“?

Lernen Sie, wie die Bindung an ein Mutual-TLS-Clientzertifikat Bearer Tokens in sendergebundene Tokens umwandelt und verhindert, dass Angreifer gestohlene Tokens wiederverwenden. Du übst OAuth2 & OpenID Connect Deep Dive mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um OAuth2 & OpenID Connect Deep Dive zu starten?

Keine Vorkenntnisse erforderlich. OAuth2 & OpenID Connect Deep Dive auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.

Wie lange dauert die Lektion „Sendergebundene Tokens mit mTLS“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser OAuth2 & OpenID Connect Deep Dive-Lektion Code schreiben und ausführen?

Ja. Jede OAuth2 & OpenID Connect Deep Dive-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Einwilligung und Benutzererfahrung
  2. Cross-Origin Resource Sharing (CORS)
  3. Front-Channel- vs. Back-Channel-Logout
  4. Sendergebundene Tokens mit mTLS
← Zurück zu OAuth2 & OpenID Connect Deep Dive