Tokens vinculados ao remetente com mTLS
Aprenda como a vinculação ao certificado do cliente por TLS mútuo transforma tokens de portador em tokens vinculados ao remetente, impedindo que tokens roubados sejam reutilizados por invasores.
Tokens vinculados ao remetente com mTLS é uma aula grátis de OAuth2 & OpenID Connect Deep Dive no CoddyKit. Esta é a aula 4 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de OAuth2 & OpenID Connect Deep Dive, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de OAuth2 & OpenID Connect Deep Dive inclui 4 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
The Bearer Token Weakness
A plain bearer token works for anyone who holds it. If it leaks via logs, a proxy, or an XSS bug, the thief can use it freely. Sender-constrained tokens fix this by binding the token to the legitimate client.
What Is mTLS?
Mutual TLS means both sides present certificates: the server proves its identity (as usual) and the client also presents a certificate. The authorization server can then bind issued tokens to that client certificate.
RFC 8705
This is standardized in RFC 8705 (OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens). It covers both client authentication via mTLS and certificate binding of access tokens.
The cnf Claim
When the AS issues a certificate-bound token, it records a confirmation (cnf) claim containing the SHA-256 thumbprint of the client certificate under the key x5t#S256.
{
"sub": "client-app",
"cnf": {
"x5t#S256": "bwcK0esc3ACC3DB2Y5_lESsXE8o9ltc05O89jdN-dg2"
}
}Resource Server Check
When the client calls an API over mTLS, the resource server computes the thumbprint of the presented certificate and compares it to the token's cnf.x5t#S256. If they differ, the token is rejected.
thumb = sha256(der_of_client_cert)
if base64url(thumb) != token.cnf['x5t#S256']:
reject('certificate binding mismatch')Why a Stolen Token Is Useless
Even with the token, an attacker cannot present the client's private key, so they cannot complete the mTLS handshake with the matching certificate. The thumbprint will not match, and the API rejects them.
mTLS Client Authentication
RFC 8705 also lets clients authenticate at the token endpoint with their certificate instead of a shared secret, using methods tls_client_auth (PKI) or self_signed_tls_client_auth.
mTLS Endpoint Aliases
Because mTLS needs a separate TLS configuration, providers publish mtls_endpoint_aliases in discovery so clients hit the certificate-bound versions of the token and other endpoints.
{
"mtls_endpoint_aliases": {
"token_endpoint": "https://mtls.op.example.com/token"
}
}mTLS vs DPoP
Both achieve sender-constraint:
- mTLS — relies on TLS-layer certificates, great for server-to-server and infrastructure with PKI.
- DPoP — application-layer proof JWTs, better for browser/public clients that cannot manage client certs.
Operational Considerations
mTLS requires certificate provisioning, rotation, and a TLS terminator that forwards the client cert to your app. Plan for cert lifecycle and ensure your reverse proxy passes the verified certificate to the resource server.
When to Adopt It
Choose mTLS-bound tokens for high-assurance, regulated, or financial-grade APIs and trusted backend services where certificate management is feasible. It dramatically raises the cost of token theft.
Quick Check
Test your mTLS binding knowledge.
Recap
mTLS sender-constrained tokens (RFC 8705) bind a token to the client's certificate.
- The token carries a
cnf.x5t#S256certificate thumbprint. - Resource servers match the presented cert's thumbprint; a stolen token without the private key fails.
- mTLS also enables certificate-based client authentication and uses mtls endpoint aliases.
- Compare with DPoP for public clients.
Aprenda OAuth2 & OpenID Connect Deep Dive com um tutor de IA — grátis
Escreva e execute código real no seu navegador, obtenha ajuda instantânea de um tutor de IA 24/7 e continue de onde parou na web ou no app.
- Cursos
- 12
- Aulas
- 48
Perguntas Frequentes
A aula “Tokens vinculados ao remetente com mTLS” é grátis?
Sim — o texto completo de “Tokens vinculados ao remetente com mTLS” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de OAuth2 & OpenID Connect Deep Dive, atualize para CoddyKit PRO. O curso de OAuth2 & OpenID Connect Deep Dive inclui 4 aulas no total.
O que vou aprender em “Tokens vinculados ao remetente com mTLS”?
Aprenda como a vinculação ao certificado do cliente por TLS mútuo transforma tokens de portador em tokens vinculados ao remetente, impedindo que tokens roubados sejam reutilizados por invasores. Você pratica OAuth2 & OpenID Connect Deep Dive com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar OAuth2 & OpenID Connect Deep Dive?
Nenhuma experiência prévia é necessária. OAuth2 & OpenID Connect Deep Dive no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 4 de 4.
Quanto tempo leva a aula “Tokens vinculados ao remetente com mTLS”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de OAuth2 & OpenID Connect Deep Dive?
Sim. Cada aula de OAuth2 & OpenID Connect Deep Dive inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Consentimento e Experiência do Usuário
- Compartilhamento de Recursos entre Origens (CORS)
- Logout pelo Canal Frontal versus Canal Posterior
- Tokens vinculados ao remetente com mTLS