AI GlossaryㅅSafety and controversy
Demonstrating Proof of Possession
An authentication technique that uses a cryptographic signature to confirm that whoever is holding a token is really the party it was issued to.
In plain words
Demonstrating Proof of Possession (DPoP) is a way to cryptographically confirm that whoever is holding an access token is really the party it was originally issued to.
Think of a hotel key card. With the old approach, anyone holding the card could open the door — if someone copied the card or intercepted it, they could get into the room just as easily as the rightful guest. DPoP is like adding a fingerprint check to that key card. Even if someone copies the card itself, they can't open the door unless they also steal the private signing key stored inside it.
Concretely, the party requesting access uses a secret key that only it holds to generate a short signature for every single request, and sends that signature along with the token. The receiving party verifies that the signature was produced by the same key that was used when the token was first issued. As a result, an attacker who only manages to steal the token can't produce the matching signature, so the stolen token can't be reused.
How it shows up in the news
The article mentions DPoP under the agent identity item in MCP (Model Context Protocol)'s new roadmap. Until now, MCP authentication relied on a human directly approving access in a browser, but going forward, browser-based approval is expected to be replaced by DPoP combined with standard token exchange to verify an AI agent's identity. It's worth noting that DPoP isn't a concept MCP invented — it's an existing authentication technique used to prevent token theft that is now being brought into agent authentication.
See also
Stories using this term
- Claude MCP Connectors Get Centralized Enterprise AuthenticationAI · 2026.08.25
- AWS connects local MCP tools to cloud agentsAI · 2026.08.06
- MCP's New Roadmap Enables Stateless, Horizontally Scalable ServersAI · 2026.08.23
- Tencent's Zhuque Lab Open-Sources AI Agent/MCP Security ScannerAI · 2026.08.21
- ComfyUI Open-Sources Local MCP ServerAI · 2026.08.22
- MiniMax unveils coding agent 'MiniMax Code 2.0'AI · 2026.08.09
