--- layout: default ---

DPoP

IANA permanent RFC 9449 reached by regulation

Registered with IANA and declared by no provider in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Reached by regulation

Basis: mandated. The law, or a technical standard the law makes binding, names this header. Only a credentialed caller can observe it in flight — the catalog can see a contract declare it, not a deployment honour it.

psd3-psr strong-customer-authentication

Carried by the dpop standard.

The registry

Statuspermanent
ReferenceRFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP)

Explore

All headers Authentication Guidance on headers.apievangelist.com