---
title: "DPoP · Highflame Glossary"
description: "Demonstrating Proof-of-Possession (RFC 9449): binds a token to a proof key so a stolen token is inert without it."
doc_version: "0.1.0"
last_updated: "2026-07-25T03:14:58.002Z"
canonical: "https://www.highflame.com/glossary/dpop"
---

[Home](/index.md)·[Glossary](/glossary.md)·DPoP

# DPoP

Demonstrating Proof-of-Possession (RFC 9449): binds a token to a proof key so a stolen token is inert without it.

Learn more: [Agent Identity](/learn/ai-agent-identity.md)

Part of [the Agent Control Fabric](/platform.md): Highflame's identity, policy, and enforcement substrate for AI agents.

[Book a demo](/contact.md) [All terms](/glossary.md)

## Keep exploring the glossary.

[

### Enterprise Managed Authorization (EMA)

An MCP extension that lets a company's identity provider decide, through corporate SSO, which MCP servers an agent may connect to. It governs admission, not what the agent does once inside.

Read →](/glossary/ema.md)[

### Guardrails

Inline detection and enforcement on an agent's prompts, tool calls, and responses: blocking unsafe actions in real time.

Read →](/glossary/guardrails.md)[

### ID-JAG

Identity Assertion JWT Authorization Grant. After SSO, the identity provider evaluates policy and issues an ID-JAG, which an MCP client exchanges for a server access token: the mechanism behind Enterprise Managed Authorization.

Read →](/glossary/id-jag.md)[

### Identity provider (IdP)

The system that issues and manages identities. Highflame extends your existing IdP to agents rather than replacing it.

Read →](/glossary/idp.md)[

### Inline enforcement

Evaluating and deciding on an action before it executes, out-of-band, rather than detecting it after the fact. Fail posture (open or closed) is set per surface.

Read →](/glossary/inline-enforcement.md)[

### Just-in-time (JIT) access

Issuing short-lived, task-scoped credentials on demand that expire when the work is done: eliminating standing access there's nothing to leak or over-grant.

Read →](/glossary/jit-access.md)

## Sitemap

Full site map: [/sitemap.md](https://www.highflame.com/sitemap.md). Machine index: [/sitemap-index.xml](https://www.highflame.com/sitemap-index.xml).
