WSO2 Changelog

  • 02 Apr, 2024

Introducing Client-Request Token Binding Type

In today's dynamic landscape, where users access applications from multiple devices and application instances, ensuring the security and integrity of user sessions poses a significant challenge. Traditional back-channel grant types, such as token exchange or password, often struggle to associate user sessions with specific devices or instances. Recognizing this challenge, Asgardeo has developed Client-Request Token Binding, a sophisticated solution that empowers developers to explicitly associate user sessions with specific devices or client instances. This feature offers flexibility and security, addressing a critical need in the realm of identity and access management.

Documentation: https://wso2.com/asgardeo/docs/references/app-settings/oidc-settings-for-app/#access-token