The JWT specification itself is not trusted by security experts. This should preclude all usage of them for anything related to security and authentication.
Very bold claim that seems to ignore all the iteration and hard-won lessons on this from the ecoystem...
https://datatracker.ietf.org/doc/html/rfc9449#name-dpop-proo...
Very bold claim that seems to ignore all the iteration and hard-won lessons on this from the ecoystem...