<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>FoxAuth blog</title><description>Notes on OAuth 2.1, OpenID Connect and running your own authorization server, written by the team building FoxAuth as we hit things worth writing down.</description><link>https://foxauth.dev/</link><language>en</language><item><title>What DPoP protects you from, and what it doesn&apos;t</title><link>https://foxauth.dev/blog/what-dpop-protects-you-from/</link><guid isPermaLink="true">https://foxauth.dev/blog/what-dpop-protects-you-from/</guid><description>A leaked access token is a password for whoever finds it. DPoP binds it to a key the client keeps: what that buys, what it costs, and when I would not bother.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate><category>dpop</category><category>tokens</category><category>security</category><author>FoxAuth</author></item></channel></rss>