Skip to content

Add a security consideration not to use VP Token as Access Token.#702

Merged
Sakurann merged 5 commits intoopenid:mainfrom
Vanderkast:vp-token-as-authz-material-security-consideration
Mar 12, 2026
Merged

Add a security consideration not to use VP Token as Access Token.#702
Sakurann merged 5 commits intoopenid:mainfrom
Vanderkast:vp-token-as-authz-material-security-consideration

Conversation

@Vanderkast
Copy link
Member

Closes #701

I would prefer making this security consideration a MUST, but I use SHOULD to avoid introducing a breaking change.

@Vanderkast Vanderkast force-pushed the vp-token-as-authz-material-security-consideration branch from d238856 to 458dcac Compare February 26, 2026 14:48
Copy link

@ve7jtb ve7jtb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would be OK with making this a Must. What is the reason for not doing that.

Other than that this is fine

Copy link
Contributor

@awoie awoie left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am in favor of making it a MUST (although it is slightly out of scope of this spec to say anything about the resource server)

Vanderkast and others added 2 commits March 9, 2026 11:09
Co-authored-by: Christian Bormann <chris.bormann@gmx.de>
* extract VP Token != Access Token into a separate security consideration.
@Sakurann Sakurann merged commit b336a4e into openid:main Mar 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a security consideration not to use VP Token as Access Token

7 participants