L33 · OAUTH 2.0
Sign a client assertion
Register a public key for a client, authenticate with a signed client assertion, and see a replayed or expired assertion refused.
Planned
Steps
Generate a key pair and register the public key for a confidential client.
What the server will check: The client has a registered public key.
Sign a client assertion with the private key and request a token with it.
What the server will check: A successful token request authenticated with a client assertion.
The private key never leaves your machine. Only a short-lived signed statement travels.
Send the same assertion again.
What the server will check: The repeated assertion was rejected.
When it opens
This lab is planned. It opens when these are in place:
- Lab setup and cleanup in your test tenant
- Signed client assertions (private_key_jwt) at the tenant token endpoint
The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.