This is the fourth post in my series on Germany’s federal API authorization blueprint. So far I have covered the posture behind the whole thing, the standards foundation they profiled rather than invented, and how clients get onboarded without a ticket. Today I want to get into the part of the design that separates a real Zero-Trust story from a marketing one: what the token can and cannot do if somebody steals it.
Never Trust the Token: DPoP and Sender-Constraining for Government APIs
calendar_today
July 28, 2026
domain
programmableweb